October 2017

View all on this date written articles further down below.
28 Oct 2017

[ICS] Progea Movicon SCADA/HMI Vulnerabilities

Vendor: Progea
Equipment: Movicon SCADA/HMI
Vulnerability: Uncontrolled Search Path Element, Unquoted Search Path or Element

ICS-CERT Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-17-290-01

CVE-ID
CVE-2017-14017
CVE-2017-14019

AFFECTED PRODUCTS
The following versions of Movicon HMI, an HMI software platform, are affected:

  • Movicon Version 11.5.1181 and prior.

 

IMPACT
Successful exploitation of these vulnerabilities could allow privilege escalation or arbitrary code execution.

Read on for details.

Read more

28 Oct 2017

[ICS] JanTek JTC-200 RS232-NET Converter Advisory Published

Vendor: JanTek
Equipment: JTC-200
Vulnerabilities: Cross-site Request Forgery, Improper Authentication

ICS-CERT Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-17-283-02

CVE-ID
CVE-2016-5789
CVE-2016-5791

AFFECTED PRODUCTS

The following versions of JTC-200, a TCP/IP converter, are affected:

  • JTC-200 all versions.


IMPACT

Successful exploitation of these vulnerabilities could allow for remote code execution on the device with elevated privileges.

Read on for details.

Read more

28 Oct 2017

[ICS] SpiderControl SCADA Web Server Improper Privilege Management Vulnerability

Vendor: SpiderControl
Equipment: SCADA Web Server
Vulnerability: Improper Privilege Management

ICS-CERT Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-17-250-01

CVE-ID
CVE-2017-12728

AFFECTED PRODUCTS

The following versions of SCADA Web Server, a software management platform, are affected:
SCADA Web Server Version 2.02.0007 and prior.

IMPACT
Successful exploitation of this vulnerability could allow authenticated system users to escalate their privileges under certain conditions.

Read on for details.

Read more

28 Oct 2017

[ICS] mySCADA myPRO Unquoted Search Path Vulnerability

Vendor: mySCADA
Equipment: myPRO
Vulnerability: Unquoted Search Path

ICS-CERT Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-17-255-01

CVE-ID
CVE-2017-12694

AFFECTED PRODUCTS
The following versions of myPRO, an HMI/SCADA management platform, are affected:

  • myPRO Versions 7.0.26 and prior.


IMPACT

Successful exploitation of this vulnerability may allow an authenticated, but non-privileged, local user to execute arbitrary code with elevated privileges.

Read on for details.

Read more