Showing posts with label AUMA. Show all posts
Showing posts with label AUMA. Show all posts

Saturday, August 12, 2023

Review – Public ICS Disclosures – Week of 8-5-23 – Part 1

This week we have 24 vendor disclosures from ABB, AUMA (2), Belden, Broadcom (3), Fujitsu, HP (6), HPE (2), Phoenix Contact (3), Rockwell, Sierra Wireless, Texas Instruments (2), Western Digital, and Zyxel.

Advisories

ABB Advisory - ABB published an advisory that describes two vulnerabilities in their Freelance AC 900F and AC 700F products.

AUMA Advisory #1 - CERT-VDE published an advisory that discusses a cross-site scripting vulnerability in their Master Station product.

AUMA Advisory #2 - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in their Master Station product.

Belden Advisory - Belden published an advisory that discusses an out-of-bounds write vulnerability in their Hirschmann Owl product.

Broadcom Advisory #1 - Broadcom published an advisory that discusses a cleartext transmission of sensitive information vulnerability in their Brocade Fabric OS.

Broadcom Advisory #2 - Broadcom published an advisory that discusses a use after free vulnerability in their Brocade Fabric OS.

Broadcom Advisory #3 - Broadcom published an advisory that discusses an uncontrolled recursion vulnerability in their Brocade Fabric OS.

Fujitsu Advisory - Fujitsu published an advisory that discusses eleven vulnerabilities in multiple products.

HP Advisory #1 - HP published an advisory that discusses three vulnerabilities in multiple products.

HP Advisory #2 - HP published an advisory that discusses five vulnerabilities in multiple products.

HP Advisory #3 - HP published an advisory that discusses an insufficient input validation vulnerability in multiple HP products.

HP Advisory #4 - HP published an advisory that discusses a privilege escalation vulnerability in multiple HP products.

HP Advisory #5 - HP published an advisory that discusses a privilege escalation vulnerability in multiple HP products.

HP Advisory #6 - HP published an advisory that discusses six vulnerabilities in multiple HP products.

HPE Advisory #1 - HPE published an advisory that discusses the Inception vulnerability in their ProLiant AMD Servers.

HPE Advisory #2 - HPE published an advisory that discusses the Inception vulnerability in their ProLiant AMD Servers.

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory that discusses eleven vulnerabilities in their PLCnext Engineer.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory that describes two vulnerabilities in their TC ROUTER and TC CLOUD CLIENT products.

Phoenix Contact Advisory #3 - Phoenix Contact published an advisory that describes 14 vulnerabilities in their WP 6xxx Web panels.

Rockwell Advisory - Rockwell published an advisory that described an incorrect calculation vulnerability in their Armor PowerFlex product.

Sierra Wireless Advisory - Sierra Wireless published an advisory that talks about recent cyberattacks on their AirLink Connection Manager products.

Texas Instruments Advisory #1 - Texas Instruments published an advisory that describes a PN reuse vulnerability in their WL18xx products.

Texas Instruments Advisory #2 - Texas Instruments published an advisory that describes an integer overflow vulnerability in their SimpleLink™ CC32XX SDK.

Western Digital Advisory - Western Digital published an advisory that describes 17 vulnerabilities in their My Cloud Home, My Cloud Home Duo and SanDisk ibi products.

Zyxel Advisory - Zyxel published an advisory that talks about a command injection vulnerability in their P660HN-T1A DSL CPE product (this product is end-of-life) which was originally corrected in 2017.

 

For more of the details about these advisories, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-258 - subscription required.

Saturday, August 13, 2022

Review – Public ICS Disclosures – Week of 8-6-22 – Part 1

This Saturday after the second Tuesday we have a large slate of disclosures to look at. For Part 1, we have 24 vendor disclosures from Auma, Fujitsu, HP (7), HPE (6), Keysight Technologies, Palo Alto Networks (2), PcVue, Schneider (4), and Sick.

Auma Advisory - CERT-VDE published an advisory that discusses 73 vulnerabilities in the Auma SIMA Master Station.

Fujitsu Advisory - Fujitsu published an advisory that discusses three vulnerabilities in a number of Fujitsu products.

HP Advisory #1 - HP published an advisory that discusses 14 vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #2 - HP published an advisory that discusses an improper restriction of XML external entity reference vulnerability in a wide variety of their PCs, notebooks and workstations.

HP Advisory #3 - HP published an advisory that discusses an improper restriction of XML external entity reference vulnerability (with a known exploit) in a wide variety of their PCs, notebooks and workstations.

HP Advisory #4 - HP published an advisory that discusses four vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #5 - HP published an advisory that discusses three vulnerabilities in in a wide variety of their PCs, notebooks and workstations.

HP Advisory #6 - HP published an advisory that discusses four vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #7 - HP published an advisory that discusses an information disclosure vulnerability in a wide variety of their PCs, notebooks and workstations.

HPE Advisory #1 - HPE published an advisory that discusses a privilege escalation vulnerability in their HPE ProLiant DL Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their ProLiant DL/ML Servers.

HPE Advisory #3 - HPE published an advisory that discusses an information disclosure vulnerability in their ProLiant DX Servers.

HPE Advisory #4 - HPE published an advisory that discusses a privilege escalation vulnerability in their Synergy Servers.

HPE Advisory #5 - HPE published an advisory that discusses an information disclosure vulnerability in their Synergy Servers.

HPE Advisory #6 - HPE published an advisory that discusses a privilege escalation vulnerability ProLiant DX Servers.

Keysight Advisory - INCIBE-CERT published an advisory that describes two vulnerabilities in the Keysight Sensor Management Server.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a reduced effectiveness of their Cortex XDR Agent anti-ransomware endpoint protection module.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a reflected amplification DOS vulnerability in their PAN-OS.

PcVue Advisory - PcVue published an advisory that describes a clear-text storage of sensitive information in their PcVue OAuth web service.

Schneider Advisory #1 - Schneider published an advisory that describes a weak password recovery vulnerability in their EcoStruxure™ Control Expert , EcoStruxure™ Process Expert, Modicon M580 and M340 products.

Schneider Advisory #2 - Schneider published an advisory that describes an integer underflow vulnerability in their Modicon PAC Controllers.

Schneider Advisory #3 - Schneider published an advisory that describes an improper restriction of operations within the bounds of a memory buffer.

Schneider Advisory #4 - Schneider published an advisory that describes an information disclosure vulnerability in their Modicon PAC Controllers.

Sick Advisory - Sick published an advisory that discusses an infinite loop vulnerability in their SIM products. This is a third-party (OpenSSL).

 

For more details on these advisories, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-e7f - subscription required.

Saturday, June 18, 2022

Review – Public ICS Disclosures – Week of 6-11-22 – Part 1

This is another busy second-Tuesday disclosure week. For Part 1 we have 23 vendor disclosures from ABB, AUMA, Genetec, Hitachi Energy, HP (2), HPE (6), OPC UA (5), PROSYS OPC, QNAP, Tanzu, TI, and VMware (2).

ABB Advisory - ABB published an advisory that describes five privilege escalation vulnerabilities in their Automation Builder, Drive Composer and Mint WorkBench products.

AUMA Advisory - CERT-VDE published an advisory that discusses a classic buffer overflow vulnerability in the AUMA SIMA² Master Station.

Genetec Advisory - Genetec published an advisory that discusses the recently reported vulnerabilities in HID Mercury controllers.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses an insecure method vulnerability in their PROMOD IV product.

HP Advisory #1 - HP published an advisory that discusses four information disclosure vulnerabilities in multiple HP products.

HP Advisory #2 - HP published an advisory that discusses an improper input validation vulnerability in multiple notebook products.

HPE Advisory #1 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Synergy Servers.

HPE Advisory #2 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Storage Products.

HPE Advisory #3 - HPE published an advisory that discusses four information disclosure vulnerabilities in their ProLiant DX Servers.

HPE Advisory #4 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Moonshot/Edgeline Servers.

HPE Advisory #5 - HPE published an advisory that discusses four information disclosure vulnerabilities in their Superdome Flex Servers.

HPE Advisory #6 - HPE published an advisory that discusses four information disclosure vulnerabilities in their ProLiant BL/DL/ML/XL/MicroServer and Apollo Servers.

OPC UA Advisory #1 - OPC UA published an advisory that describes an uncontrolled resource consumption vulnerability in their .NET Standard Stack.

OPC UA Advisory #2 - OPC UA published an advisory that describes an incorrect implementation of authentication algorithm vulnerability in their .NET Standard Stack.

OPC UA Advisory #3 - OPC UA published an advisory that describes an uncontrolled resource consumption vulnerability in their .NET Standard Stack.

OPC UA Advisory #4 - OPC UA published an advisory that describes a memory allocation with excessive size value vulnerability in their .NET Standard Stack.

OPC UA Advisory #5 - OPC UA published an advisory that describes an infinite loop vulnerability in their .NET Standard Stack.

PROSYS OPC Advisory - PROSYS published an advisory that discusses a security feature bypass vulnerability (with publicly available exploit) in their OPC products.

QNAP Advisory - QNAP published an advisory that discusses a ransomware campaign that appears to target QNAP NAS devices running outdated versions of QTS 4.x.

Tanzu Advisory - Tanzu published an advisory that describes a denial of service vulnerability in their Spring Cloud product.

TI Advisory - TI published an advisory that describes missing ECC input validations on CC1310 and CC1350 devices.

VMware Advisory #1 - VMware published an advisory that describes an information disclosure vulnerability in their HCX product.

VMware Advisory #2 – VMware published an advisory that discusses four information disclosure vulnerabilities in their ESXi product.


For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-446 - subscription required.

 
/* Use this with templates/template-twocol.html */