Today CISA’s NCCIC-ICS published two control system security
advisories for products from Mitsubishi Electric and Horner Automation.

360 Mobile Vision - 360mobilevision.com North & South Carolina Security products and Systems Installations for Commercial and Residential - $55 Hourly Rate. ACCESS CONTROL, INTRUSION ALARM, ACCESS CONTROLLED GATES, INTERCOMS AND CCTV INSTALL OR REPAIR 360 Mobile Vision - 360mobilevision.com is committed to excellence in every aspect of our business. We uphold a standard of integrity bound by fairness, honesty and personal responsibility. Our distinction is the quality of service we bring to our customers. Accurate knowledge of our trade combined with ability is what makes us true professionals. Above all, we are watchful of our customers interests, and make their concerns the basis of our business.

Mitsubishi Advisory

This advisory
describes an improper authentication vulnerability in the Mitsubishi GOT
products. The vulnerability is self-reported. Mitsubishi provides generic
mitigation measures pending development of an updated version.

NCCIC-ICS reports that an uncharacterized attacker could
remotely exploit the vulnerability to allow an attacker to gain unauthorized
access.

Horner Advisory

This advisory
describes two vulnerabilities in the Horner Automation Cscape control system application
programming software. The vulnerabilities were reported by Sharon Brizinov of
Claroty. Horner has a new version that mitigates the vulnerability. There is no
indication that Brizinov has been provided an opportunity to verify the
efficacy of the fix.

The two reported vulnerabilities are:

• Improper input validation – CVE-2021-22678,
and

• Improper access control – CVE-2021-22682

NCCIC-ICS reports that an uncharacterized attacker with
uncharacterized access could exploit the vulnerability to allow code execution
in the context of the current process or locally escalate privileges.

By admin