Showing posts with label Ads-tec. Show all posts
Showing posts with label Ads-tec. Show all posts

Saturday, February 24, 2024

Review – Public ICS Disclosures – Week of 2-17-24

This week we have 13 vendor disclosures from ADT-TEC Industrial IT, B&R, Elecom (2), Hitachi, HP, HPE, Palo Alto Networks, Sierra Wireless, VMware (2), WAGO, and Zyxel. There are two vendor updates from Cisco and Elecom. There are also 14 researcher reports for products from Imaging Data Commons, Inductive Automation, Sante, SourceForge (8), Weston (3). Finally, we have three exploits for products from Mayurik (2) and QNAP.

Advisories

ADS-TEC Advisory - CERT-VDE published an advisory that discusses an exposure of resource to wrong sphere vulnerability in multiple ADS-TEC DVG-IRF industrial routers.

B&R Advisory - B&R published an advisory that describes an insufficient communication encryption vulnerability in their Automation Studio and Technology Guarding products.

Elecom Advisory #1 - JP CERT published an advisory that describes two vulnerabilities in the Elecom wireless LAN routers.

Elecom Advisory #2 - JP CERT published an advisory that describes an OS command injection vulnerability in the Elecom wireless LAN routers.

Hitachi Advisory - Hitachi published an advisory that describes an EL injection vulnerability in their Global Link Manager.

HP Advisory - HP published an advisory that discusses a service location protocol vulnerability (listed in CISA’s Known Exploited Vulnerability (KEV) Catalog) in their Tera2 Zero Client and Remote Workstation Card.

HPE Advisory - HPE published an advisory that discusses the generation of error message containing sensitive information vulnerability in their IceWall products.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses the Leaky-Vessels vulnerabilities.

Sierra Wireless Advisory - Sierra Wireless published an advisory that discusses three vulnerabilities in their s EM919x and EM929x

cellular modules.

VMware Advisory #1 - VMware published an advisory that describes a privilege escalation vulnerability in their Aria Operations product.

VMware Advisory #2 - VMware published an advisory that describes two vulnerabilities in their deprecated VMware Enhanced Authentication Plug-in.

WAGO Advisory - CERT-VDE published an advisory that discusses the Terrapin-Attack vulnerability.

Zyxel published an advisory that describes four vulnerabilities in their firewall and AP products.

Zyxel Advisory - Zyxel published an advisory that describes four vulnerabilities in their firewall and AP products.

Updates

Cisco Update - Cisco published an update for their cURL and libcurl vulnerability advisory that was originally published on October 11th, 2023 and most recently updated on November 8th, 2023.

Elecom Update - JP-CERT published an update for their ELECOM and LOGITEC network devices advisory that was originally published on October 5th, 2020 and most recently updated on January 23rd, 2024.

Researcher Reports

Imaging Data Commons Report - Cisco Talos published a report describing two use-after-free vulnerabilities in the Imaging Data Commons libdicom.

Inductive Automation Report - The Zero Day Initiative published two reports for individual vulnerabilities in the Inductive Automation Ignition product.

Sante Report - ZDI published a report describing an improper input validation vulnerability in the Sante PACS Server.

SourceForge Reports - Cisco Talos published eight reports describing individual vulnerabilities in the SourceForge Biosig Project.

Weston Reports - Cisco Talos published three reports describing four vulnerabilities in the Weston Embedded product.

Exploits

Mayurik Exploit #1 - Nu11secur1ty published an exploit for an SQL injection vulnerability in the Mayurik Best Petrol Pump Management Software.

Mayurik Exploit #2 - SoSPiro published an exploit for a remote shell upload vulnerability in the Mayurik Best Petrol Pump Management Software.

QNAP Exploit - Spencer McIntyre published a Metasploit module for an OS command injection vulnerability in the QNAP QTS and QuTS hero products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-1cf - subscription required.

Saturday, May 13, 2023

Review – Public ICS Disclosures – Week of 5-6-23 – Part 1 -

For Part 1 this week we have 34 vendor disclosures from Ads-Tec, Aruba, CONTEC, Fujitsu, HP (5), HPE (7), Insyde (2), Milestone (2), Palo Alto Networks (2), Rockwell (2), Tanzu (7), Texas Instruments, VMware, and WatchGuard.

Advisories

Ads-Tec Advisory - CERT-VDE published an advisory that discusses 18 vulnerabilities in the ads-tec IRF1000, IRF2000, and IRF3000 firewalls and routers.

Aruba Advisory - Aruba published an advisory that describes 13 vulnerabilities in their Access Points product.

CONTEC Advisory - JP-CERT published an advisory that describes five vulnerabilities in the CONTEC SolarView Compact product.

Fujitsu Advisory - Fujitsu published an advisory that discusses two vulnerabilities addressed in the 2023.2 INTEL Platform Update.

HP Advisory #1 - HP published an advisory that discusses 18 vulnerabilities in their products utilizing the AMD Client UEFI Firmware.

HP Advisory #2 - HP published an advisory that discusses four vulnerabilities in their products utilizing the Intel Virtual RAID on CPU.

HP Advisory #3 - HP published an advisory that discusses two vulnerabilities in their products utilizing the Intel 2023.2 IPU – BIOS.

HP Advisory #4 - HP published an advisory that discusses two vulnerabilities in their PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware.

HPE Advisory #1 - HPE published an advisory that discusses an exposure of information to wrong sphere vulnerability in their Proliant DX Servers.

HPE Advisory #2 - HPE published an advisory that discusses an exposure of information to wrong sphere vulnerability in their Apollo, XL Servers.

HPE Advisory #3 - HPE published an advisory that discusses an exposure of information to wrong sphere vulnerability in their Synergy Servers.

HPE Advisory #4 - HPE published an advisory that discusses an exposure of information to wrong sphere vulnerability in their StoreEasy Servers.

HPE Advisory #5 - HPE published an advisory that discusses 15 vulnerabilities in their ProLiant Gen10 and Gen10 Plus Servers.

HPE Advisory #6 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML Servers.

HPE Advisory #7 - HPE published an advisory that discusses an exposure of information to wrong sphere vulnerability in their Superdome Flex Servers.

Insyde Advisory #1 - Insyde published an advisory that discusses an unchecked return value vulnerability in their BIOS PNG decoder libs.

Insyde Advisory #2 - Insyde published an advisory that describes an insufficient input validation vulnerability in various Intel Mobile Platforms.

Milestone Advisory #1 - Milestone published an advisory that describes a remote code execution vulnerability in their Management Server.

Milestone Advisory #2 - Milestone published an advisory that describes a remote code execution vulnerability in their Event Server.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a file disclosure vulnerability in their PAN-OS. The vulnerability was reported by Alex Hordijk.

Palo Alto Network Advisory #2 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS software on Panorama appliances.

Rockwell Advisory #1 - Rockwell published an advisory that describes nine cross-site scripting vulnerabilities in their ArmorStart® ST 281E, and 284EE products.

Rockwell Advisory #2 - Rockwell published an advisory that describes a cross-site request forgery vulnerability in their FactoryTalk Vantagepoint product.

Tanzu Advisory #1 - Tanzu published an advisory that discusses an out-of-bounds write vulnerability in multiple Tanzu products.

Tanzu Advisory #2 - Tanzu published an advisory that discusses an off-by-one error vulnerability in multiple Tanzu products.

Tanzu Advisory #3 - Tanzu published an advisory that discusses an off-by-one error vulnerability in multiple Tanzu products.

Tanzu Advisory #4 - Tanzu published an advisory that discusses four vulnerabilities in multiple Tanzu products.

Tanzu Advisory #5 - Tanzu published an advisory that discusses a use of cryptographically weak PRNG vulnerability in multiple Tanzu products.

Tanzu Advisory #6 - Tanzu published an advisory that discusses six vulnerabilities in multiple Tanzu products.

Tanzu Advisory #7 - Tanzu published an advisory that discusses two vulnerabilities in multiple Tanzu products.

Texas Instruments Advisory - Texas Instruments published an advisory that describes a missing logic check vulnerability in their Wi-SUN® Stack.

VMware Advisory - VMware published an advisory that describes four vulnerabilities in their Aria Operations product.

WatchGuard Advisory - WatchGuard published an advisory that describes an arbitrary file read vulnerability in their Fireware OS products.

 

For more details on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-ba5 - subscription required.

 
/* Use this with templates/template-twocol.html */