Saturday, March 25, 2023
AI Home Security
No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology
No Result
View All Result
Morning News
No Result
View All Result
Home Cyber Security

CISA Warns of Flaws in Siemens, GE Digital, and Contec Industrial Control Systems

justmattg by justmattg
January 22, 2023
in Cyber Security
0
CISA Warns of Flaws in Siemens, GE Digital, and Contec Industrial Control Systems
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

READ ALSO

Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data

Red Teaming at Scale to Uncover Your Big Unknowns


Jan 18, 2023Ravie LakshmananICS/SCADA Security

Industrial Control Systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published four Industrial Control Systems (ICS) advisories, calling out several security flaws affecting products from Siemens, GE Digital, and Contec.

The most critical of the issues have been identified in Siemens SINEC INS that could lead to remote code execution via a path traversal flaw (CVE-2022-45092, CVSS score: 9.9) and command injection (CVE-2022-2068, CVSS score: 9.8).

Also patched by Siemens is an authentication bypass vulnerability in llhttp parser (CVE-2022-35256, CVSS score: 9.8) as well as an out-of-bounds write bug in the OpenSSL library (CVE-2022-2274, CVSS score: 9.8) that could be exploited to trigger remote code execution.

The German automation company, in December 2022, released Service Pack 2 Update 1 software to mitigate the flaws.

Separately, a critical flaw has also been revealed in GE Digital’s Proficy Historian solution that could result in code execution regardless of authentication status. The issue, tracked as CVE-2022-46732 (CVSS score: 9.8), impacts Proficy Historian versions 7.0 and higher, and has been remediated in Proficy Historian 2023.

“An attacker can take advantage of this fact and bypass the historian authentication by impersonating a local service,” Uri Katz, security researcher at industrial security firm Claroty, said. “This allows remote attackers the ability to log in to any GE Proficy Historian server and force it to perform unauthorized actions.”

CISA also updated an ICS advisory that was published last month, detailing a critical command injection vulnerability in Contec CONPROSYS HMI System (CVE-2022-44456, CVSS score: 10.0) that could permit a remote attacker to send specially crafted requests to execute arbitrary commands.

While this shortcoming was patched by Contec in version 3.4.5, the software has since been found to be vulnerable to four additional defects that could lead to information disclosure and unauthorized access.

Users of CONPROSYS HMI System are recommended to update to version 3.5.0 or later, in addition to taking steps to minimize network exposure and isolate such devices from business networks.

The advisories come less than a week after CISA released 12 such alerts warning of critical flaws impacting software from Sewio, InHand Networks, Sauter Controls, and Siemens.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Related Posts

Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data
Cyber Security

Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data

March 25, 2023
Red Teaming at Scale to Uncover Your Big Unknowns
Cyber Security

Red Teaming at Scale to Uncover Your Big Unknowns

March 24, 2023
Inside the High Risk of 3rd-Party SaaS Apps
Cyber Security

Inside the High Risk of 3rd-Party SaaS Apps

March 24, 2023
Open Source Vulnerabilities Still Pose a Big Challenge for Security Teams
Cyber Security

Open Source Vulnerabilities Still Pose a Big Challenge for Security Teams

March 24, 2023
Fake ChatGPT Chrome Browser Extension Caught Hijacking Facebook Accounts
Cyber Security

Fake ChatGPT Chrome Browser Extension Caught Hijacking Facebook Accounts

March 24, 2023
2023 Cybersecurity Maturity Report Reveals Organizational Unpreparedness for Cyberattacks
Cyber Security

2023 Cybersecurity Maturity Report Reveals Organizational Unpreparedness for Cyberattacks

March 23, 2023
Next Post
Zoho ManageEngine PoC Exploit to be Released Soon

Zoho ManageEngine PoC Exploit to be Released Soon

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR NEWS

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players’ Systems

February 13, 2023
Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

Trickbot Members Sanctioned for Pandemic-Era Ransomware Hits

February 11, 2023
The New Threats to Cryptocurrency Users

The New Threats to Cryptocurrency Users

February 12, 2023
Do you know who is watching you?

Do you know who is watching you?

January 2, 2023
PopID announces big customer deployment for face biometric payments in UAE

PopID announces big customer deployment for face biometric payments in UAE

February 14, 2023

EDITOR'S PICK

Every device getting Matter support in 2023

Every device getting Matter support in 2023

January 28, 2023
Cyberattack on Fintech Firm Disrupts Derivatives Trading Globally

Cyberattack on Fintech Firm Disrupts Derivatives Trading Globally

February 2, 2023
IceFire Ransomware Portends a Broader Shift From Windows to Linux

IceFire Ransomware Portends a Broader Shift From Windows to Linux

March 9, 2023
Researchers Share New Insights Into RIG Exploit Kit Malware’s Operations

Researchers Share New Insights Into RIG Exploit Kit Malware’s Operations

February 28, 2023

About

We bring you the best news & updates related to Home security, Cyber security and Biometric technology. Keep visiting our website for latest updates.

Follow us

Categories

  • Biometric Technology
  • Cyber Security
  • Home Security

Recent Posts

  • Another Big BIPA Ruling, Paris Olympics Legislation, NEOM Airlines, and More: Identity News Digest
  • Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal Data
  • The NSA and CISA Highlight On-device Privacy: Identity News Digest
  • Red Teaming at Scale to Uncover Your Big Unknowns
  • Privacy Policy
  • Contact Us

© 2023 AI Home Security - All rights reserved.

No Result
View All Result
  • Home
  • Home Security
  • Cyber Security
  • Biometric Technology

© 2023 AI Home Security - All rights reserved.