SCADA software provider, ICONICS patched two separate vulnerabilities in its GENESIS 32 and BizViz product lines, according to ICS-CERT.

One vulnerability involved a design issue in a GENESIS32 ActiveX control that can set an arbitrary domain to the trusted zone. The other vulnerability includes a crash in the Security Login controls used by GENESIS32 due to a buffer overflow.

RELATED STORIES
Siemens PLC Security Alert
WinCC Vulnerabilities Patched
Attack Vector: Buffer Overflows Top Threat
‘Improper Input Validation’ Top ICS Weakness

ICS-CERT (Industrial Control Systems Cyber Emergency Response Team) received a report on the vulnerabilities from independent security researchers Billy Rios and Terry McCorkle.

ICONICS validated the researchers’ claims for multiple versions of GENESIS32 and BizViz and they released a patch that addresses the vulnerabilities. The researchers validated the patch mitigates the reported vulnerabilities.

Schneider Bold

The vulnerabilities exist in two ICONICS products. The products and versions affected in the trusted zone vulnerability are:
• GENESIS32 – Version 9.21, including Workbench/WebHMI components
• BizViz – Version 9.21

The products and versions affected in the Security Login vulnerability are:
• GENESIS32 – Versions 8.05, 9.0, 9.1 and 9.2
• BizViz – Versions 8.05, 9.0, 9.1 and 9.2

Successful exploitation of the trusted zone vulnerability could result in arbitrary domain intrusion into the trusted zone, introducing the potential for remote code execution.

ICONICS is a U.S.-based company with offices in the U.S., UK, Netherlands, Italy, India, Germany, France, Czech Republic, China, and Australia.

The affected products, GENESIS32 and BizViz, are web-based SCADA systems. According to ICONICS, GENESIS32 deploys across several sectors including manufacturing, building automation, oil and gas, water and wastewater, electric utilities, and others. ICONICS estimates these products mainly see use in the United States and Europe with a small percentage in Asia.

in the Trusted Zone vulnerability, exploitation of the ICONICS GENESIS Workbench32/WebHMI component SetTrustedZone Policy vulnerability requires creation of a website that can load and use the IcoSetServer ActiveX control in a way that inserts an arbitrary domain into the Trusted Zone.

With the Security Login vulnerability, a successful exploit could cause a buffer overflow resulting in a denial of service and potential remote code execution. Exploitation of this vulnerability requires creation of a specially crafted password that exceeds a specified length and contains executable code.

All these vulnerabilities are remotely exploitable and there are no known exploits specifically target this vulnerability.

Patches and an ICONICS whitepaper are available from the ICONICS website.

ISSSource

Pin It on Pinterest

Share This