security advisory

[ICS] ELNet Energy meter & Electrical powermeter – multiple vulnerabilities

ELNet Energy meter & Electrical Powermeter vulnerabilities – another case of poor software security practices.

security advisory

[ICS] Multiple vulnerabilities – Powerlogic/Schneider Electric IONXXXX series Smart Meters

Multiple security issues in Powerlogic/Schneider Electric IONXXXX series power meters

The following IONXXXX series power meter versions are affected:
ION73XX series,
ION75XX series,
ION76XX series,
ION8650 series,
ION8800 series, and
PM5XXX series.

security advisory

Halliburton LogView Pro 9.7.5 – (.cgm/.tif/.tiff/.tifh) Crash PoC

Halliburton LogView Pro 9.7.5 – (.cgm/.tif/.tiff/.tifh) Denial of Service Crash exploit

https://www.exploit-db.com/exploits/40192/

security advisory

mySCADAPro v7 Local Privilege Escalation

mySCADAPro v7 Local Privilege Escalation

Reporting a vulnerability in mySCADAPro version 7 (current version).

Vendor: mySCADA Technologies s.r.o.
Product web page: https://www.myscada.org/
Affected application: myscadaPro
Affected version: v7 (Current version)

security advisory

RS232-NET Converter (model JTC-200) – Multiple vulnerabilities

Exploiting RS232-NET Converter (model JTC-200)

Seen deployed in:
CHTD, Chunghwa Telecom Co., Ltd. (Taiwan)
HiNet (Taiwan & China)
PT Comunicacoes (Portugal)
Sony Network Taiwan Limited (Taiwan)
Vodafone Portugal (Portugal)

security advisory

CIMA DocuClass Enterprise Content Management – Multiple Vulnerabilities

On a recent pentest, I came across CIMA DocuClass Enterprise Content Management application. I found multiple security vulnerabilities which can lead to unauthorized access to stored documents, access to underlying database, and code execution on the server via SQL Injection.

No response from vendor as expected. Read on.

security advisory

[ICS] ICS-ALERT-16-182-01 published – Sierra Wireless Raven XE & XT vulnerabilities

Couple of days back, I posted multiple vulnerabilities in Sierra Wireless Raven XE & XT devices on Full Disclosure list, and here:

http://ipositivesecurity.com/2016/06/25/ics-sierra-wireless-airlink-raven-xe-industrial-3g-gateway-multiple-vulnerabilities/

ICS-CERT team confirmed yesterday they have released an alert on this report as well now:
https://ics-cert.us-cert.gov/alerts/ICS-ALERT-16-182-01