Summary:
CISA has released three Industrial Control Systems (ICS) advisories on October 5, 2023, to inform users and administrators about current security issues, vulnerabilities, and exploits affecting ICS.
ICSA-23-278-01: Hitachi Energy AFS65x, AFF66x, AFS67x, and AFR67x Series Products
The advisory warns of four (4) vulnerabilities in Hitachi Energy’s AFS65x, AFF66x, AFS67x, and AFR67x series products, which could allow an attacker to execute arbitrary code, gain access to sensitive information, and manipulate system operations. The vulnerabilities stem from issues with insufficient input validation, incorrect implementation of encryption, and weak authentication. CISA recommends that Hitachi Energy users and administrators update firmware, configure proper access controls, and implement robust encryption to mitigate the risks.
ICSA-23-278-02: Qognify NiceVision
This advisory addresses seven (7) vulnerabilities in Qognify’s NiceVision video management system. The vulnerabilities, ranging from medium to high severity, could allow an attacker to access sensitive information, manipulate system configurations, and inject malware into the system. The issues are attributed to insufficient authentication, weak encryption, and inadequate input validation. CISA advises Qognify users and administrators to apply security patches, restrict access to authorized personnel, and implement robust authentication and encryption mechanisms to protect against exploitation.
ICSA-23-278-03: Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch
This advisory highlights three (3) vulnerabilities in Mitsubishi Electric’s CC-Link IE TSN Industrial Managed Switch. The vulnerabilities, categorized as medium to high severity, could allow an attacker to manipulate system configurations, inject malware, and access sensitive information. The issues stem from incorrect implementation of encryption, insufficient authentication, and weak input validation. CISA recommends Mitsubishi Electric users and administrators to update firmware, restrict access to authorized personnel, and implement robust authentication and encryption mechanisms to mitigate the risks.
In summary, CISA encourages users and administrators to review the released ICS advisories for technical details and mitigations to address the identified vulnerabilities and prevent potential security breaches.