Saturday, July 9, 2022

Review – Public ICS Disclosures – Week of 7-2-22

 The 4th of July week is still apparently vacation time for lots of folks which may be why we have a relatively slow week for ICS disclosures. This week we have five vendor disclosures from HPE, Insyde, QNAP, Sante, and Watchguard. We have four vendor updates from Aruba, Festo, and HPE (2).

HPE Advisory - HPE published an advisory that discusses seventeen vulnerabilities (one with known exploit) in their Apache Web Server.

Insyde Advisory - Insyde published an advisory that discusses 22 vulnerabilities (20 with known exploits) in their InsydeH2O BIOS.

QNAP Advisory - QNAP published an advisory that discusses ransomware attacks on NAS products with SMB services exposed to the internet.

Sante Advisory - Incibe-CERT published an advisory that describes an SQL injection vulnerability in the Sante PACS Server, a software used for processing images in DICOM format.

Watchguard Advisory - Watchguard published an advisory that discusses an improper authentication vulnerability in their Fireware OS.

Aruba Update - Aruba published an update for their Expat XML advisory that was originally published on May 17th, 2022 and most recently updated on June 1st, 2022.

Festo Update - CERT-VDE published an update for their Festo Advisory that was originally published on June 8th, 2022.

HPE Update #1 - HPE published an update for their Superdome Flex advisory that that originally published on June 7th, 2022 and most recently updated on June 21st, 2022.

HPE Update #2 - HPE published an update for their Superdome Flex advisory that was originally published on June 14th, 2022 and most recently updated on June 21st, 2022.

 

For more details about these disclosures, including links to 3rd party advisories and exploit, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */