HomeSecurityCISA published multiple advisories for ICS

CISA has published multiple advisories for ICS

The Cybersecurity and Infrastructure Security Administration (CISA) announced two critical updates for Industrial Control Systems (ICS) on December 5, 2024.

CISA has published multiple advisories for ICS

With these updates, CISA sheds light on current security issues, vulnerabilities, and exploits in ICS.

The two updates are:

  • ICSA-24-340-01
  • ICSA-24-340-02

See also: CISA: Warns of vulnerabilities in CyberPanel, North Grid, ProjectSend and Zyxel Firewalls

CISA experts discovered that these advisory updates mainly focus on “AutomationDirect C-More EA9 Programming Software” and “Planet Technology Planet WGS-804HPT”.

AutomationDirect C-More EA9 programming software

C-More EA9 Programming software, versions 6.78 and earlier, is affected by multiple stack-based buffer overflow vulnerabilities. These vulnerabilities , which have been identified as CVE-2024-11609, CVE-2024-11610, and CVE-2024-11611, all have a CVSS v4 base score of 8.4, indicating high severity.

Successful exploitation of these vulnerabilities can lead to:

  • Memory corruption
  • Remote code execution
  • Possible system compromise

The vulnerabilities are due to improper handling of input files, allowing hackers to execute arbitrary code remotely.

AutomationDirect recommends updating the C-More EA9 HMI to version 6.79. If an immediate update is not possible, several interim measures are recommended:

  • Isolation of engineering workstations
  • Implement strict access controls
  • Use of application whitelisting
  • Strengthening workstation security
  • Monitoring and recording system activities
  • Conduct regular risk assessments

Read more: VMware patches serious vulnerabilities in Aria Operations

Planet Technology Planet WGS-804HPT

The Planet WGS-804HPT industrial switch, version v1.305b210531, is affected by three critical vulnerabilities:

  • Stack-based Buffer Overflow (CVE-2024-48871)
  • Operating System Command Injection (CVE-2024-52320)
  • Integer Overflow (CVE-2024-52558)

The first two vulnerabilities have a CVSS v4 base score of 9.3, while the integer leak vulnerability has a score of 6.9.

These vulnerabilities could allow hackers to:

  • Remote code execution
  • Inject malicious commands
  • Bring down the system

The vulnerabilities are exploitable via malformed HTTP requests, posing significant risk to affected systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Industrial Control Systems (ICS)

Planet Technology recommends upgrading to version 1.305b241111 or later. CISA also advises users to:

See also: CISA adds Array Networks vulnerability to KEV List

  • Minimize network exposure for control system devices
  • Implement firewalls and isolate control systems from business networks
  • Use secure remote access methods, such as VPN
  • Conduct impact analysis and risk assessment before implementing defensive measures

These ICS advisory updates highlight the critical importance of promptly addressing vulnerabilities in industrial control systems to maintain the security and integrity of critical infrastructure sectors worldwide.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS