SCADA StrangeLove

Tuesday, December 16, 2014

Well, Honeywell

New knowledge about Honeywell Experion Process Knowledge System. Yes, you must patch it.
Yes, it's all about grep +1 SSRF.

Thanks to Alexander Tlyapov, Gleb Gritsai, Kirill Nesterov, Artem Chaykin and Ilya Karpov

Honeywell advisory/patch:
https://www.honeywellprocess.com/library/support/Public/Documents/ExperionPKS.R311.Server.Patch282.PAR1-2VNCSKZ_SCN.pdf

Sorry for the delay. It can wait.



PS.

http://osvdb.org/show/osvdb/115235
http://osvdb.org/show/osvdb/115236
http://osvdb.org/show/osvdb/115237
http://osvdb.org/show/osvdb/115239
http://osvdb.org/show/osvdb/115238
http://osvdb.org/show/osvdb/115240
http://osvdb.org/show/osvdb/115241
http://osvdb.org/show/osvdb/115242
http://osvdb.org/show/osvdb/115243
http://osvdb.org/show/osvdb/115244
http://osvdb.org/show/osvdb/115245
http://osvdb.org/show/osvdb/115246
http://osvdb.org/show/osvdb/115247
http://osvdb.org/show/osvdb/115248
http://osvdb.org/show/osvdb/115249
http://osvdb.org/show/osvdb/115250
http://osvdb.org/show/osvdb/115251
http://osvdb.org/show/osvdb/115253
http://osvdb.org/show/osvdb/115233
http://osvdb.org/show/osvdb/115234
+1
http://osvdb.org/show/osvdb/115252
Posted by SCADAStrangeLove at 12:12 PM
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: digital substation, energy, EPK, honewell, smartgrid, Vulnerabilities
Location: İstanbul, Turkey

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

About

My photo
SCADAStrangeLove
Group of security researchers focused on ICS/SCADA security to save Humanity from industrial disaster and to keep Purity Of Essence
View my complete profile
Follow @scadasl
http://scada.sl/
http://scadastrangelove.blogspot.com/
@scadasl
Alexander Timorin
Alexander Tlyapov
Alexander Zaitsev
Alexey Osipov
Andrey Medov
Artem Chaykin
Denis Baranov
Dmitry Efanov
Dmitry Nagibin
Dmitry Serebryannikov
Dmitry Sklyarov
Evgeny Ermakov
Gleb Gritsai
Ilya Karpov
Ivan Poliyanchuk
Kirill Nesterov
Roman Ilin
Roman Polushin
Sergey Bobrov
Sergey Drozdov
Sergey Gordeychik
Sergey Scherbel
Sergey Sidorov
Timur Yunusov
Valentin Shilnenkov
Vladimir Kochetkov
Vyacheslav Egoshin
Yuri Goltsev
Yuriy Dyachenko

Blog Archive

  • ►  2021 (2)
    • ►  August (1)
    • ►  January (1)
  • ►  2020 (15)
    • ►  December (2)
    • ►  November (1)
    • ►  October (2)
    • ►  August (1)
    • ►  July (3)
    • ►  June (2)
    • ►  May (2)
    • ►  April (2)
  • ►  2019 (16)
    • ►  December (2)
    • ►  November (1)
    • ►  October (4)
    • ►  September (2)
    • ►  August (1)
    • ►  July (1)
    • ►  May (2)
    • ►  April (1)
    • ►  March (2)
  • ►  2018 (19)
    • ►  December (2)
    • ►  November (5)
    • ►  October (4)
    • ►  September (1)
    • ►  August (3)
    • ►  June (1)
    • ►  March (1)
    • ►  February (2)
  • ►  2017 (2)
    • ►  October (1)
    • ►  September (1)
  • ►  2016 (5)
    • ►  December (1)
    • ►  August (1)
    • ►  July (2)
    • ►  February (1)
  • ►  2015 (17)
    • ►  December (5)
    • ►  October (1)
    • ►  September (3)
    • ►  August (2)
    • ►  July (1)
    • ►  May (3)
    • ►  February (2)
  • ▼  2014 (17)
    • ▼  December (3)
      • 31C3: Too Smart Grid in da Cloud ++
      • SOS! Secure Open SmartGrids!
      • Well, Honeywell
    • ►  November (1)
    • ►  October (2)
    • ►  September (2)
    • ►  July (1)
    • ►  June (2)
    • ►  May (2)
    • ►  March (2)
    • ►  February (1)
    • ►  January (1)
  • ►  2013 (32)
    • ►  December (4)
    • ►  November (3)
    • ►  October (1)
    • ►  September (2)
    • ►  August (2)
    • ►  July (1)
    • ►  June (2)
    • ►  May (2)
    • ►  March (3)
    • ►  February (2)
    • ►  January (10)
  • ►  2012 (20)
    • ►  December (4)
    • ►  November (4)
    • ►  September (3)
    • ►  July (5)
    • ►  June (3)
    • ►  May (1)
Powered by Blogger.