Saturday, January 7, 2023

Review – Public ICS Disclosures – Week of 12-31-22

A very light week for the beginning of the new year. This week we have four vendor disclosures from FortiGuard. We also have updates from Dell and Medtronic.

Vendor Disclosures

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a header injection vulnerability in their FortiWeb API.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiTester GUI and API.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiPortal management interface.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiADC.

Vendor Updates

Dell Update - Dell published an update for their Wyse Management Suite advisory that was originally published on December 19th, 2022.

Medtronic Update - Medtronic published an update for their MiniMed Insulin pump advisory that was originally published on June 27th, 2019.

 

For more details about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-267 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */