ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Warns of Critical ICS Flaws in Hitachi, mySCADA, ICL, and Nexx Products

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-25359
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.

On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.

NVD description · AI analysis pending
9.137% PoC
  • iclinks scadaflex ii firmware
  • iclinks weblib
CVE-2022-3682
A vulnerability exists in the SDM600 file permission validation.

A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and uploading a specially crafted message to the system node, which could result in Arbitrary code Executing. This issue affects: All SDM600 versions prior to version 1.2 FP3 HF4 (Build Nr. 1.2.23000.291) List of CPEs: * cpe:2.3:a:hitachienergy:sdm600:1.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.1:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.9002.257:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.10002.257:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.11002.149:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.12002.222:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.13002.72:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.44:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.92:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.108:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.182:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.257:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.342:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.447:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.481:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.506:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.14002.566:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.20000.3174:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.21000.291:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.21000.931:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.21000.105:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:sdm600:1.2.23000.291:*:*:*:*:*:*:*

NVD description · AI analysis pending
8.8<1%
  • hitachienergy sdm600
CVE-2023-1748
The listed versions of Nexx Smart Home devices use hard-coded credentials.

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile application or the affected firmware could view the credentials and access the MQ Telemetry Server (MQTT) server and the ability to remotely control garage doors or smart plugs for any customer.

NVD description · AI analysis pending
10.0<1%
  • getnexx nxal-100 firmware
  • getnexx nxg-100b firmware
  • getnexx nxpg-100w firmware
  • +1 more
CVE-2023-28384
+4 in the same advisory: …28400 …28716 …29150 …29169
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

NVD description · AI analysis pending
8.845%
  • myscada mypro
Full article416 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 07, 2023Industrial Control System

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published eight Industrial Control Systems (ICS) advisories warning of critical flaws affecting products from Hitachi Energy, mySCADA Technologies, Industrial Control Links, and Nexx.

Topping the list is CVE-2022-3682 (CVSS score: 9.9), impacting Hitachi Energy's MicroSCADA System Data Manager SDM600 that could allow an attacker to take remote control of the product.

The flaw stems from an issue with file permission validation, thereby permitting an adversary to upload a specially crafted message to the system, leading to arbitrary code execution.

Hitachi Energy has released SDM600 1.3.0.1339 to mitigate the issue for SDM600 versions prior to version 1.2 FP3 HF4 (Build Nr. 1.2.23000.291).

Another set of five critical vulnerabilities – CVE-2023-28400, CVE-2023-28716, CVE-2023-28384, CVE-2023-29169, and CVE-2023-29150 (CVSS scores: 9.9) – relate to command injection bugs present in mySCADA myPRO versions 8.26.0 and prior.

"Successful exploitation of these vulnerabilities could allow an authenticated user to inject arbitrary operating system commands," CISA warned, urging users to update to version 8.29.0 or higher.

A critical security bug has also been disclosed in Industrial Control Links ScadaFlex II SCADA Controllers (CVE-2022-25359, CVSS score: 9.1) that could allow an authenticated attacker to overwrite, delete, or create files.

"Industrial Control Links has relayed that they are closing their business," the agency said. "This product may be considered end-of-life; continued support for this product may be unavailable."

Users are recommended to minimize network exposure, isolate control system networks from business networks, and place them behind firewalls to address potential risks.

Rounding off the list are five unpatched shortcomings, including one critical bug (CVE-2023-1748, CVSS score: 9.3), impacting garage door controllers, smart plugs, and smart alarms sold by Nexx.

The vulnerabilities that could enable threat actors to crack open home garage doors, take over smart plugs, and gain remote control of smart alarms, according to security researcher Sam Sabetan, who discovered and reported the issues.

The following versions of Nexx smart home devices are affected -

  • Nexx Garage Door Controller (NXG-100B, NXG-200) - Version nxg200v-p3-4-1 and prior
  • Nexx Smart Plug (NXPG-100W) - Version nxpg100cv4-0-0 and prior
  • Nexx Smart Alarm (NXAL-100) - Version nxal100v-p1-9-1and prior

"Successful exploitation of these vulnerabilities could allow an attacker to receive sensitive information, execute application programmable interface (API) requests, or hijack devices," CISA said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/04/cisa-warns-of-critical-ics-flaws-in.html