Saturday , September 7 2024
Rockwell automation

Microsoft Uncovers Flaws in Rockwell Automation PanelView Plus

Microsoft’s cybersecurity team found two major vulnerabilities in Rockwell Automation’s PanelView Plus, a widely used human-machine interface in industrial settings.

There are two vulnerabilities, CVE-2023-2071 and CVE-2023-29464, that can be used by attackers without authentication. They can use these vulnerabilities for remote code execution (RCE) and denial-of-service (DoS) attacks.

Cisco released security updates for two critical security flaws

CISCO released security updates for two critical security flaws impacting its smart Licensing Utility that could allow unauthenticated, remote attackers...
Read More
Cisco released security updates for two critical security flaws

OpenBAS: Cutting-edge breach and attack simulation platform

OpenBAS is a platform that helps organizations to plan, schedule, and conduct crisis exercises, adversary simulations, and breach simulations. OpenBAS...
Read More
OpenBAS: Cutting-edge breach and attack simulation platform

Critical Security Flaws Patched in Zyxel Networking Devices

Zyxel has released software updates to fix a serious security issue in certain access point (AP) and security router versions....
Read More
Critical Security Flaws Patched in Zyxel Networking Devices

CVE-2024-38811: CEV In VMware Fusion Unveiled

VMware released a security advisory for a major vulnerability in the VMware Fusion product. This vulnerability could be exploited by...
Read More
CVE-2024-38811: CEV In VMware Fusion Unveiled

CERT-IN Warns Vulnerabilities in Palo Alto Networks applications

Indian Computer Emergency Response Team (CERT-IN) issued advisories about multiple vulnerabilities in various Palo Alto Networks applications. Attackers could exploit...
Read More
CERT-IN Warns Vulnerabilities in Palo Alto Networks applications

How Malaysia’s Data Centre Industry Poised for Growth

Malaysia is quickly becoming a leading choice for investing in data centers. It aims to generate RM3.6 billion (US$781 million)...
Read More
How Malaysia’s Data Centre Industry Poised for Growth

RansomHub exfiltrated data over 210 victims: US alert

US authorities have issued a cybersecurity advisory about a ransomware group called RansomHub. The group is thought to have stolen data...
Read More
RansomHub exfiltrated data over 210 victims: US alert

Godzilla Fileless Backdoor Exploits Atlassian Confluence flaw

There is a new way to attack Atlassian Confluence using the vulnerability CVE-2023-22527. The Confluence Data Center and Server products...
Read More
Godzilla Fileless Backdoor Exploits Atlassian Confluence flaw

New Cicada ransomware targets VMware ESXi servers

The Cicada3301 ransomware is made in Rust and attacks Windows and Linux/ESXi hosts. Truesec researchers examined a version that targets...
Read More
New Cicada ransomware targets VMware ESXi servers

Monday hits two UK bank apps causes outages

Lloyds Bank and Virgin Money's internet banking services were down on Monday, causing trouble for users to access and view...
Read More
Monday hits two UK bank apps causes outages

The RCE vulnerability in PanelView Plus can be exploited to upload a malicious DLL and run unauthorized code on the device. The DoS vulnerability, on the other hand, crashes the device by sending a crafted buffer it can’t handle.

Microsoft issued a warning on Tuesday about the serious risk that vulnerabilities in these devices pose to organizations that use them for important processes. These vulnerabilities could allow unauthorized remote control and disruption of critical operations.

Microsoft’s Defender for IoT research team noticed communication between two devices using the Common Industrial Protocol (CIP) during the discovery process.

After more research, a remote registry query function was found in the HMI, particularly the PanelView Plus. This led to the team speculating about possible vulnerabilities that could be used to access sensitive system keys or take control of the device.

Researchers found DLLs in the PanelView Plus firmware for processing CIP class IDs. They discovered that one DLL could be used to upload and run malicious DLL files, confirming their theory about remote-control vulnerabilities.

In May and July 2023, Microsoft shared these findings with Rockwell Automation through its Coordinated Vulnerability Disclosure (CVD) program. Rockwell responded by issuing security patches and advisories in September and October 2023.

Microsoft encourages all PanelView Plus users to apply these patches as soon as possible to reduce potential risks.

Microsoft recommends disconnecting critical devices such as PLCs, routers, and PCs from the internet and segregating them, regardless of whether they use Rockwell’s FactoryTalk View. They also suggest limiting access to CIP devices only to authorized components to enhance overall security measures.

Check Also

coding

Godzilla Fileless Backdoor Exploits Atlassian Confluence flaw

There is a new way to attack Atlassian Confluence using the vulnerability CVE-2023-22527. The Confluence …

Leave a Reply

Your email address will not be published. Required fields are marked *