Today CISA’s NCCIC-ICS published seven control system security advisories for products from Viidure, MikroTik, Anjvision, Baicells, VIVOTEK, TopTech, and Lantronix.
Advisories
Viidure Advisory - This advisory describes two vulnerabilities in the Viidure Dashcam Android Application. The vulnerabilities were reported to CISA by Bugrahan Karahan. CISA notes that: “Viidure did not respond to CISA's coordination attempts.”
Mikrotik Advisory - This advisory describes an integer underflow vulnerability in the MikroTik RouterOS. The vulnerability was reported to CISA by an anonymous researcher.
Anjvision Advisory -This advisory describes an initialization of resource with an insecure default vulnerability in the Anjvision YSSD-RTMP-H5 firmware. The vulnerabilities were reported to CISA by Andrew Lee. CISA notes that: “Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities.”
Baicells Advisory - This advisory describes an uncaught exception vulnerability in the Baicells Technologies Nova 430H eNodeB. The vulnerability was reported to CISA by Qiqing Huang. CISA notes that: “Baicells has not responded to requests to work with CISA to mitigate this vulnerability.”
VIVOTEK Advisory - This advisory describes a command injection vulnerability in the VIVOTEK Camera Firmware. The vulnerability was originally reported by Larry Cashdollar with proof-of-concept code.
Toptech Advisory - This advisory describes 10 vulnerabilities in the Toptech Systems TMS7 and Tophat 7 terminal management systems. The vulnerabilities were reported by Sachin Shetty and Roy Duisters of Shell CyberDefence.
Lantronix Advisory - This advisory describes two vulnerabilities in the Lantronix G520 Series Cellular Gateway. The vulnerabilities were reported to CISA by Ievgen Bondarenko.
No comments:
Post a Comment