CISA Warns of Flaws in Siemens, GE Digital, and Contec Industrial Control Systems
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-2068 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shel In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze). NVD description · AI analysis pending | 7.3 | 95% |
| — | ||
| CVE-2022-2274 | The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue. NVD description · AI analysis pending | 9.8 | 47% | PoC |
| — | |
| CVE-2022-35256 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. NVD description · AI analysis pending | 6.5 | 3% | PoC |
| — | |
| CVE-2022-44456 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. NVD description · AI analysis pending | 9.8 | 70% |
| — | ||
| CVE-2022-45092 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system. An attacker might leverage this to trigger remote code execution on the affected component. NVD description · AI analysis pending | 8.8 | 31% |
| — | ||
| CVE-2022-46732 | Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status. Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status. NVD description · AI analysis pending | 9.8 | <1% |
| — |
Full article389 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 18, 2023ICS/SCADA Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published four Industrial Control Systems (ICS) advisories, calling out several security flaws affecting products from Siemens, GE Digital, and Contec.
The most critical of the issues have been identified in Siemens SINEC INS that could lead to remote code execution via a path traversal flaw (CVE-2022-45092, CVSS score: 9.9) and command injection (CVE-2022-2068, CVSS score: 9.8).
Also patched by Siemens is an authentication bypass vulnerability in llhttp parser (CVE-2022-35256, CVSS score: 9.8) as well as an out-of-bounds write bug in the OpenSSL library (CVE-2022-2274, CVSS score: 9.8) that could be exploited to trigger remote code execution.
The German automation company, in December 2022, released Service Pack 2 Update 1 software to mitigate the flaws.
Separately, a critical flaw has also been revealed in GE Digital's Proficy Historian solution that could result in code execution regardless of authentication status. The issue, tracked as CVE-2022-46732 (CVSS score: 9.8), impacts Proficy Historian versions 7.0 and higher, and has been remediated in Proficy Historian 2023.
"An attacker can take advantage of this fact and bypass the historian authentication by impersonating a local service," Uri Katz, security researcher at industrial security firm Claroty, said. "This allows remote attackers the ability to log in to any GE Proficy Historian server and force it to perform unauthorized actions."
CISA also updated an ICS advisory that was published last month, detailing a critical command injection vulnerability in Contec CONPROSYS HMI System (CVE-2022-44456, CVSS score: 10.0) that could permit a remote attacker to send specially crafted requests to execute arbitrary commands.
While this shortcoming was patched by Contec in version 3.4.5, the software has since been found to be vulnerable to four additional defects that could lead to information disclosure and unauthorized access.
Users of CONPROSYS HMI System are recommended to update to version 3.5.0 or later, in addition to taking steps to minimize network exposure and isolate such devices from business networks.
The advisories come less than a week after CISA released 12 such alerts warning of critical flaws impacting software from Sewio, InHand Networks, Sauter Controls, and Siemens.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/01/cisa-warns-of-flaws-in-siemens-ge.html