← Back to home
ICSA-17-234-01  ·  Published 2017-08-22  ·  View on CISA ICS-CERT ↗

Automated Logic Corporation WebCTRL, i-VU, SiteScan

CVSS 8.3 HIGH

Risk Summary

ATTENTION: Remotely exploitable/low skill level to exploit.

Remediations

  • ALC provides support for WebCTRL, i-Vu, SiteScan Web versions 6.0 and greater. Those users using prior versions, including 5.5 and 5.2, must upgrade to supported versions in order to install these mitigation patches.
  • ALC applications should always be installed and maintained in accordance with the guidelines found here:
  • In addition ALC has released the following patches, which address these vulnerabilities:
  • WebCTRL 6.0: Cumulative Patch #13
  • WebCTRL 6.1: Cumulative Patch #7
  • WebCTRL 6.5: Cumulative Patch #7 + WS65_Security_Update2.update
  • These patch releases may be obtained on the ALC accounts web site or calling Technical Support at 770-429-3002
  • i-Vu 6.0, Cumulative Patch #13
  • i-Vu 6.5, Cumulative Patch #7 + WS65_Security_Update2.update
  • The patch release may be obtained by calling Technical Support at 800-277-9852
  • SiteScan Web Version 6.1, Cumulative Patch #7, and
  • SiteScan Web Version 6.5, Cumulative Patch #7 + WS65_Security_Update2.update.
  • These patches may be obtained by contacting Liebert Services at 1-800-543-2378.

Affected Vendors

Automated Logic Corporation (ALC)

Affected Products (5)

Automated Logic Corporation (ALC) · ALC WebCTRL i-Vu SiteScan Web <= 6.5
Automated Logic Corporation (ALC) · ALC WebCTRL i-Vu <= 6.0
Automated Logic Corporation (ALC) · ALC WebCTRL i-Vu SiteScan Web <= 5.5
Automated Logic Corporation (ALC) · ALC WebCTRL i-Vu SiteScan Web <= 5.2
Automated Logic Corporation (ALC) · ALC WebCTRL SiteScan Web <= 6.1

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more