Security News > 2023 > January > CISA Warns of Flaws Affecting Industrial Control Systems from Major Manufacturers

CISA Warns of Flaws Affecting Industrial Control Systems from Major Manufacturers
2023-01-16 10:47

The U.S. Cybersecurity and Infrastructure Security Agency has released several Industrial Control Systems advisories warning of critical security flaws affecting products from Sewio, InHand Networks, Sauter Controls, and Siemens.

The most severe of the flaws relate to Sewio's RTLS Studio, which could be exploited by an attacker to "Obtain unauthorized access to the server, alter information, create a denial-of-service condition, gain escalated privileges, and execute arbitrary code," according to CISA. This includes CVE-2022-45444, a case of hard-coded passwords for select users in the application's database that potentially grant remote adversaries unrestricted access.

Also notable are two command injection flaws and an out-of-bounds write vulnerability that could result in denial-of-service condition or code execution.

The vulnerabilities impact RTLS Studio version 2.0.0 up to and including version 2.6.2.

CISA, in a second alert, highlighted a set of five security defects in InHand Networks InRouter 302 and InRouter 615, including CVE-2023-22600, that could lead to command injection, information disclosure, and code execution.

Security vulnerabilities have also been disclosed in Sauter Controls Nova 220, Nova 230, Nova 106, and moduNet300 that could allow unauthorized visibility to sensitive information and remote code execution.


News URL

https://thehackernews.com/2023/01/cisa-warns-for-flaws-affecting.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-01-18 CVE-2022-45444 Use of Hard-coded Credentials vulnerability in Sewio Real-Time Location System Studio
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the application’s database.
network
low complexity
sewio CWE-798
critical
9.8
2023-01-12 CVE-2023-22600 Unspecified vulnerability in Inhandnetworks Inrouter302 Firmware and Inrouter615-S Firmware
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-284: Improper Access Control.
network
high complexity
inhandnetworks
8.1