{"id":2082,"date":"2025-02-19T10:03:40","date_gmt":"2025-02-19T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/19\/cisa-releases-two-new-ics-advisories-exploits-following-vulnerabilities\/"},"modified":"2025-02-19T10:03:40","modified_gmt":"2025-02-19T10:03:40","slug":"cisa-releases-two-new-ics-advisories-exploits-following-vulnerabilities","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/19\/cisa-releases-two-new-ics-advisories-exploits-following-vulnerabilities\/","title":{"rendered":"CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities"},"content":{"rendered":"<p>    CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Cybersecurity and Infrastructure Security Agency (CISA) released two Industrial Control Systems <a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-20-ics-advisories\/\" target=\"_blank\" rel=\"noreferrer noopener\">(ICS) advisories<\/a>, addressing critical vulnerabilities in Delta Electronics CNCSoft-G2 and Rockwell Automation GuardLogix controllers.\u00a0<\/p>\n<p>These advisories highlight exploitable flaws in systems widely used in manufacturing, energy, and critical infrastructure sectors.\u00a0<\/p>\n<p>The disclosures underscore escalating risks to operational technology (OT) environments, where successful exploitation could enable remote code execution, <a href=\"https:\/\/cybersecuritynews.com\/multiple-vulnerabilities-in-cisco-snmp-for-ios-software\/\">denial-of-service (DoS)<\/a> attacks and operational disruption.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Delta Electronics CNCSoft-G2 Vulnerabilities (ICSA-24-191-01)<\/strong><\/h2>\n<p>The Delta Electronics CNCSoft-G2 advisory details four memory corruption vulnerabilities (CVE-2024-39880 to CVE-2024-39883) affecting versions prior to 2.1.0.10.\u00a0<\/p>\n<p>These flaws, discovered by Trend Micro\u2019s Zero Day Initiative (ZDI), stem from improper validation of user-supplied data in the parsing of DPAX files\u2014a proprietary format used in computer numerical control (CNC) systems.\u00a0<\/p>\n<p>Attackers can exploit these vulnerabilities by tricking users into opening malicious files or visiting compromised web pages, leading to:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Stack-based buffer overflow (CVE-2024-39880)<\/strong>: Allows <a href=\"https:\/\/cybersecuritynews.com\/hpe-aruba-networking-clearpass-policy-manager-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">arbitrary code execution<\/a> via crafted input exceeding fixed buffer limits.<\/li>\n<li>\n<strong>Out-of-bounds write (CVE-2024-39881)<\/strong>: Enables memory corruption by writing data beyond allocated boundaries.<\/li>\n<li>\n<strong>Out-of-bounds read (CVE-2024-39882)<\/strong>: Permits unauthorized access to sensitive memory contents.<\/li>\n<li>\n<strong>Heap-based buffer overflow (CVE-2024-39883)<\/strong>: Triggers code execution via manipulated heap allocations.<\/li>\n<\/ul>\n<p>All vulnerabilities carry a CVSS v4 base score of 8.4, reflecting high exploitability and impact.\u00a0<\/p>\n<p>Mitigation requires updating to CNCSoft-G2 v2.1.0.10 and isolating control systems from untrusted networks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Rockwell Automation GuardLogix Controllers (ICSA-25-035-02)<\/strong><\/h2>\n<p>The Rockwell Automation GuardLogix 5380 and 5580 advisory addresses CVE-2025-24478, a <a href=\"https:\/\/cybersecuritynews.com\/ios-messenger-dos-vulnerability-emoji\/\" target=\"_blank\" rel=\"noreferrer noopener\">DoS vulnerability<\/a> in firmware versions prior to V33.017, V34.014, V35.013, and V36.011.<\/p>\n<p>The flaw arises from improper handling of exceptional conditions in CIP (Common Industrial Protocol) message processing.\u00a0<\/p>\n<p>Remote, non-privileged attackers can send malicious requests to trigger a major nonrecoverable fault (MNRF), forcing controllers into a halted state and requiring manual reinitialization.<\/p>\n<p>With a CVSS v3.1 score of 6.5 and v4 score of 7.1, the vulnerability poses significant risks to industrial automation systems reliant on continuous operation.\u00a0<\/p>\n<p>Rockwell recommends updating firmware, restricting network access via CIP Security, and implementing VPNs for remote connections.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Mitigation Strategies and Broader Implications<\/strong><\/h2>\n<p>CISA emphasizes proactive measures to mitigate risks:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Network Segmentation: <\/strong>Isolate ICS devices from corporate IT networks and the internet.<\/li>\n<li>\n<strong>Patch Management: <\/strong>Apply vendor-supplied updates immediately. Delta Electronics and Rockwell have released patches for their respective systems.<\/li>\n<li>\n<strong>Defense-in-Depth:<\/strong> Deploy firewalls, intrusion detection systems (IDS), and application allowlisting.<\/li>\n<li>\n<strong>Secure Remote Access:<\/strong> Use VPNs with multi-factor authentication (MFA) and audit access logs.<\/li>\n<\/ul>\n<p>The advisories arrive amid heightened scrutiny of OT security following high-profile attacks on critical infrastructure.\u00a0<\/p>\n<p>As <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/02\/18\/cisa-releases-two-industrial-control-systems-advisories\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> in CISA\u2019s alert, \u201cThese vulnerabilities could be exploited by threat actors to disrupt essential services, emphasizing the need for rapid remediation\u201d.<\/p>\n<p>CISA\u2019s latest advisories highlight persistent vulnerabilities in industrial control systems, urging immediate action to safeguard critical infrastructure.\u00a0<\/p>\n<p>Exploits require low attack complexity, so organizations must prioritize <a href=\"https:\/\/cybersecuritynews.com\/pandora-malware-attacks-android-tvs\/\">firmware updates<\/a>, network hardening, and adherence to frameworks like NIST SP 800-82 for ICS security.\u00a0<\/p>\n<p>As adversarial tactics evolve, collaboration between vendors, auditors, and federal agencies remains critical to maintaining resilience in an increasingly connected industrial landscape.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-two-new-ics-advisories\/\">CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-two-new-ics-advisories\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Releases Two New ICS Advisories Exploits Following Vulnerabilities The Cybersecurity and Infrastructure Security Agency (CISA) released two Industrial Control Systems (ICS) advisories, addressing critical vulnerabilities in Delta Electronics CNCSoft-G2 and Rockwell Automation GuardLogix controllers.\u00a0 These advisories highlight exploitable flaws in systems widely used in manufacturing, energy, and critical infrastructure sectors.\u00a0 The disclosures underscore escalating [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-2082","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2082"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2082"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2082\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2082"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2082"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2082"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}