Showing posts with label Advantech. Show all posts
Showing posts with label Advantech. Show all posts

Sunday, February 1, 2026

Review – Public ICS Disclosures – Week of 1-24-26 – Part 2

For Part 2 we have six additional vendor disclosures from dormakaba (3), Splunk, and WatchGuard (2). We have bulk vendor updates from Broadcom (7). There are six additional vendor updates from HP, HPE (3), Palo Alto Networks, and VMware. We also have a researcher report on vulnerabilities in products from IDIS. Finally, we have an exploit for products from Advantech.

Advisories

Dormakaba Advisory #1 - Dormakaba published an advisory that describes 12 vulnerabilities in their Access Manager product.

Dormakaba Advisory #2 - Dormakaba published an advisory that describes seven vulnerabilities in their Kaba exos 9300 systems.

Dormakaba Advisory #3 - Dormakaba published an advisory that describes a debug messages revealing unnecessary information vulnerability in their registration Unit 9002 Generation K5.

Splunk Advisory - Splunk published an advisory that discusses an improper handling of length parameter inconsistency vulnerability (with publicly available exploits, listed in CISA’s KEV catalog) in their Enterprise product.

WatchGuard Advisory #1 - WatchGuard published an advisory that discusses a privilege escalation vulnerability in their Mobile VPN with IPSec client for Windows.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes an LDAP injection vulnerability in their Fireware OS product.

Bulk Vendor Updates – Broadcom

Brocade Fabric OS (10.x and 9.2.x Releases) Vulnerability Disclosures,

OS command injection vulnerability in OpenSSH (CVE-2023-51385),

Brocade ASCG Vulnerability Disclosures,

Brocade SANnav Vulnerability Disclosures,

CVE-2023-31928 - XSS vulnerability in Brocade Webtools,

Potential Denial of Service exploit in Net-SNMP 5.8 through 5.9.3, and

Linux Kernel Vulnerable to Dangling Pointer via Garbage Collector Racing Against Connect() in AF_UNIX Module.

Bulk Vendor Updates – Hitachi Energy

Cybersecurity Advisory - Reboot Vulnerability in Hitachi Energy Relion 670/650 and SAM600-IO series products,

Cybersecurity Advisory - Improper Input Validation Vulnerability in Hitachi Energy’s Relion® 670/650/SAM600-IO series Product,

Cybersecurity Advisory - OpenSSL Vulnerabilities in Hitachi Energy’s Relion® 670, 650, SAM600-IO series Product,

Cybersecurity Advisory - Update package validation Vulnerability in Hitachi Energy’s Relion® 670, 650 and SAM600-IO Series Products, and

Cybersecurity Advisory - IEC 61850 MMS-Server Vulnerability in Hitachi Energy’s Relion® 670, 650 series and SAM600-IO Products.

Updates

HP Update - HP published an update for their Intel Ethernet I219 Software advisory that was originally published on February 11th, 2025, and most recently updated on April 24th, 2025.

HPE Update #1 - HPE published an update for their OneView Software advisory that was originally published on December 17th, 2025, and most recently updated on December 26th, 2025.

HPE Update #2 - HPE published an update for their Aruba Networking Virtual Intranet Access advisory that was originally published on January 13th, 2026.

HPE Update #3 - HPE published an update for their Aruba Networking AOS-8 advisory that was originally published on January 13th, 2026.

Palo Alto Networks Update - PAN published an update for their GlobalProtect Gateway and Portal advisory that was originally published on January 14th, 2026, and most recently updated on January 16th, 2026.

VMware Update - Broadcom published an update for the VMware vCenter Server advisory that was originally published on June 17th, 2024.

Researcher Reports

IDIS Report - Claroty published a report that describes an argument injection vulnerability in the IDIS ICM Viewer.

Exploits

Advantech Exploit - Indoushka published an exploit for an SQL Injection vulnerability in the Advantech IoTSuite and IoT Edge products.

 

For more information about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-2c5 - subscription required.

Sunday, January 18, 2026

Review – Public ICS Disclosures – Week of 1-10-26 – Part 2

For Part 2 we have seven additional vendor disclosures from ABB, Advantech, FortiGuard, Phoenix Contact, Supermicro, and Wireshark (2). We also have bulk vendor updates from Siemens (14). Finally, there are also five vendor updates from FortiGuard, HPE, and Schneider (3).

Advisories  

ABB Advisory - ABB published an advisory that describes an incorrect implementation of authentication algorithm vulnerability in their Ability OPTIMAX product.

Advantech Advisory - CSA published an advisory that describes an SQL injection vulnerability (with publicly available exploit) in the Advantech IoTSuite and IoT Edge products.

FortiGuard Advisory - FortiGuard published an advisory that describes an OS command injection vulnerability (with publicly available exploit) in their FortiSIEM products.

Phoenix Contact Advisory - Phoenix Contact published an advisory that describes a code injection vulnerability in their TC ROUTER and CLOUD CLIENT Industrial mobile network routers.

Supermicro Advisory - Supermicro published an advisory that describes two improper verification of cryptographic signature vulnerabilities in their BMC firmware.

Wireshark Advisory #1 - Wireshark published an advisory that describes an infinite loop vulnerability in their HTTP3 dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes a crash vulnerability in their SOME/IP-SD dissector.

Wireshark Advisory #3 - Wireshark published an advisory that describes a crash vulnerability in their IEEE 802.11 dissector.

Wireshark Advisory #4 - Wireshark published an advisory that describes a crash vulnerability in their BLF file parser.

Vendor Updates

FortiGuard Update - FortiGuard published an update for their `Host` header injection advisory that was originally published on January 14th, 2025.

NOTE: This advisory was not listed on the FortiGuard PSIRT website.

HPE Update - HPE published an update for their OneView Software advisory that was originally published on December 17th, 2025.

Schneider Update #1 - Schneider published an update for their Modicon Controllers M340 advisory that was originally published on November 12th, 2024, and most recently updated on April 8th, 2025.

Schneider Update #2 - Schneider published an update for their RemoteConnect advisory that was originally published on January 14th, 20225.

Schneider Update #3 - Schneider published an update for their Uni-Telway Driver advisory that was originally published on February 11th, 2025, and most recently updated on July 8th, 2025.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-5df - subscription required.

Thursday, December 18, 2025

Review – 8 Advisories and 1 Update Published – 12-18-25

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Axis Communications, Rockwell Automation, Advantech, Siemens, Mitsubishi Electric, National Instruments, Schneider Electric, and Inductive Automation. They also updated an advisory for products from Mitsubishi.

Advisories

Axis Advisory - This advisory describes four vulnerabilities in multiple Axis surveillance products.

Rockwell Advisory - This advisory describes two vulnerabilities in the Rockwell Micro8xx PLCs.

Advantech Advisory - This advisory describes five vulnerabilities in the Advantech WebAccess/SCADA product.

Siemens Advisory - This advisory describes an improper verification of source of a communications channel vulnerability in the Siemens Interniche IP-Stack used in a wide range of Siemens products.

NOTE: I briefly mentioned this vulnerability on December 14th, 2025.

Mitsubishi Advisory - This advisory describes an OS command injection vulnerability in multiple Mitsubishi Electric Iconics Digital Solutions products.

NI Advisory - This advisory describes nine vulnerabilities in the NI LabView product.

Schneider Advisory - This advisory discusses a deserialization of untrusted data vulnerability in the Schneider EcoStruxure Foxboro DCS Advisor.

NOTE: I briefly discussed this vulnerability on December 14th, 2025.

Inductive Advisory - This advisory describes an execution with unnecessary privileges vulnerability in the Inductive Ignition product.

Updates

Mitsubishi Update - This update provides additional information on the CNC Series advisory that was originally published on October 17th, 2024, and most recently updated on March 18th, 2025

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-and-1-update-published-f72 - subscription required.

Sunday, December 7, 2025

Review – Public ICS Disclosures – Week of 11-29-25 – Part 2

For Part 2 we have 19 bulk disclosures from Splunk (10) and WatchGuard (9). We have two additional vendor disclosures from Wireshark. There are four vendor updates from Advantech, Moxa (2), and VMware. There are ten researcher reports on vulnerabilities in a product from Socomec. Finally, we have two exploits for products from Broadcom and PX4.

Block Disclosures

Bulk Disclosures – Splunk

SPL commands allowlist controls bypass in Splunk MCP Server app through "run_splunk_query" MCP tool,

Third-Party Package Updates in Splunk Enterprise - December 2025,

Improper Input Validation in "label" column field in Splunk Secure Gateway App,

Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise,

Incorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation or upgrade,

Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade,

Stored Cross-Site scripting (XSS) through Anchor Tag "href" in Navigation Bar Collections in Splunk Enterprise,

Unauthenticated Log Injection in Splunk Enterprise,

Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app, and

URL validation bypass through Views Dashboard in Splunk Enterprise

Bulk Disclosures – WatchGuard

WatchGuard Firebox Boot Time System Integrity Check Bypass,

WatchGuard Firebox XPath Injection Vulnerability in Web CGI,

WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless Controller,

WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration,

WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration,

WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration,

WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping Command,

WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec Configuration,

WatchGuard Firebox iked Memory Corruption Vulnerability,

WatchGuard Firebox Authenticated Out of Bounds Write in certd,

Advisories

Wireshark Advisory #1 - Wireshark published an advisory that describes an infinite loop vulnerability (with publicly available exploit) in their MEGACO dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes an improperly controlled sequential memory allocation vulnerability (with publicly available exploit) in their HTTP3 dissector.

Updates

Advantech Update - Advantech published an update for their WISE-DeviceOn advisory that was originally published on November 18th, 2025.

Moxa Update #1 - Moxa published an update for their Secure Routers advisory that was originally published on April 2nd, 2025, and most recently updated on October 27th, 2025.

Moxa Update #2 - Moxa published an update for their Secure Routers advisory that was originally published on April 2nd, 2025, and most recently updated on October 27th, 2025.

VMware Update - Broadcom published an update for their vCenter Server advisory that was originally published on September 21s, 2021, and most recently updated on September 24th, 2021.

Researcher Reports

Socomec Reports - Cisco Talos published ten reports for 14 vulnerabilities in the Socomec DIRIS Digiware M-70.

Exploits

Broadcom Exploit - Laginimaineb published an exploit for an improper restriction of operations within the bounds of a memory buffer in the Broadcom BCM4355C0 Wi-Fi chips.

PX 4 Exploit - Indoushka published an exploit for a stack-based buffer overflow vulnerability in the PX4 drone autopilot.


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-2dc - subscription required.


Thursday, December 4, 2025

Review – 7 Advisories and 2 Updates Published – 12-4-25

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Advantech, Solis Cloud, Sunbird, Johnson Controls (2), MAXHIB, and Mitsubishi. They also updated advisories for products from Johnson Controls and Consilium.

Advisories

Advantech Advisory - This advisory describes an SQL injection vulnerability in the Advantech iView product.

SolisCloud Advisory - This advisory describes an authorization bypass through a user controlled key vulnerability in the SolisCloud Monitoring Platform.

Sunbird Advisory - This advisory describes two vulnerabilities in the Sunbird DCIM dcTrack and Power IQ products.

Johnson Controls Advisory #1 - This advisory describes an improper validation of certificate expiration vulnerability in the Johnson Controls iStar products.

Johnson Controls Advisory #2 - This advisory describes a forced browsing vulnerability in the Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace.

MAXHUB Advisory - This advisory describes a weak password recovery mechanism for forgotten password vulnerability in the MAXHUB Pivot client.

Mitsubishi Advisory - This advisory describes a cleartext storage of sensitive information vulnerability in the Mitsubishi GX Works2 product.

NOTE: I briefly discussed this vulnerability on November 29th, 2025.

Updates

Johnson Control Update - This update provides additional information on the FX80 and FX90 advisory that was originally published on August 7th, 2025.

Consilium Update - This update provides additional information on the CS5000 Fire Panel advisory that was originally published on May 29th, 2025.

NOTE: The original CISA advisory noted that no fix was planned for these vulnerabilities. See my May 29th, 2025, post for more information.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-67d - subscription required.

Sunday, November 9, 2025

Review – Public ICS Disclosures – Week of 11-1-25 – Part 1

This week we bulk disclosures from QNAP (11). We also have nine additional vendor disclosures from ABB, Advantech, Eaton (2), Meinberg, Mitsubishi, Moxa, and Philips (2).

Bulk Disclosure – QNAP

Vulnerability in QuMagie,

Multiple Vulnerabilities in Download Station,

Multiple Vulnerabilities in File Station 5,

Vulnerability in Notification Center,

Vulnerability in Qsync Central,

Multiple Vulnerabilities in QuLog Center,

Vulnerability in QuMagie,

Vulnerability in Malware Remover (PWN2OWN 2025),

Multiple Vulnerabilities in QTS and QuTS hero (PWN2OWN 2025),

Multiple Vulnerabilities in HBS 3 Hybrid Backup Sync (PWN2ONW 2025),

Vulnerability in Hyper Data Protector (PWN2OWN 2025)

Advisories

ABB Advisory - ABB published an advisory that discusses a path traversal vulnerability (with publicly available exploit) in their PMC 600 protection and control IED manager.

Advantech Advisory - Advantech published an advisory that describes 12 vulnerabilities in their WebAccess/VPN portal.

Eaton Advisory #1 - Eaton published an advisory that describes a missing authentication for critical function vulnerability in their Brightlayer Software Suite.

Eaton Advisory #2 - Eaton published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their Brightlayer Software Suite.

Meinberg Advisory - Meinberg published an advisory that discusses 12 vulnerabilities (3 with publicly available exploits) in their Lantime product. These are third-party vulnerabilities.

Mitsubishi Advisory - Mitsubishi published an advisory that describes an improper validation of specified quantity in input vulnerability in their MELSEC iQ-F Series CPU module.

Moxa Advisory - Moxa published an advisory that discusses an uncontrolled resource consumption vulnerability (with publicly available exploit) in multiple Moxa products.

Philips Advisory #1 - Philips published an advisory that discuses an ASP.NET core HTTP request/response smuggling vulnerability.

Philips Advisory #2 - Philips published an advisory that discusses the Glassworm malware campaign.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-ab7 - subscription required.

Thursday, November 6, 2025

Review – 3 Advisories and 1 Update Published – 10-6-25

Today CISA’s NCCIC-ICS published three control system security advisories for products from ABB, Ubia, and Advantech. They also updated an advisory for products from Hitachi Energy.

Advisories

ABB Advisory - This advisory describes four vulnerabilities (with publicly available exploits) in the ABB FLXeon Controllers.

Ubia Advisory - This advisory describes an insufficiently protected credentials vulnerability in the Ubia Ubox camera.

Advantech Advisory - This advisory describes four vulnerabilities in the Advantech DeviceOn/iEdge, an IoT management platform.

Updates

Hitachi Energy Update - This update provides additional information on the Asset Suite advisory that was originally published on October 9th, 2025.

Note: I briefly discussed the updated Hitachi Energy advisory on November 1st, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-published-2dc - subscription required.

Thursday, July 10, 2025

Review – 10 Advisories and 3 Updates Published – 7-10-25

Today CISA’s NCCIC-ICS published ten control system security advisories for products from AAR Railroad Electronics Standards, KUNBUS, Advantech, Delta Electronics, and Siemens (6). They also update advisories for products from IDEC Products, ECOVACS, and KUNBUS.

NOTE: Siemens published three other advisories on Tuesday. I will cover them in the Public ICS Disclosure blog post this weekend.

Advisories

AAR Advisory - This advisory describes a weak authentication vulnerability in the Association of American Railroads (AAR) End-of-Train and Head-of-Train remote linking protocol.

KUNBUS Advisory - This advisory describes an incorrect implementation of authentication algorithm vulnerability in the KUNBUS Revolution Pi OS and RevPi Webstatus.

Advantech Advisory - This advisory describes ten vulnerabilities in the Advantech iView product.

Delta Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Delta DTM Soft product.

SIPROTEC Advisory - This advisory describes a use of GET request method with sensitive query strings vulnerability in the Siemens SIPROTEC products.

TIA Advisory #1 - This advisory describes an upload of file with dangerous type vulnerability in the Siemens TIA Project-Server and TIA Portal products.

TIA Advisory #2 - This advisory describes two vulnerabilities in the Siemens TIA Administrator.

SIMATIC Advisory - This advisory describes an improper input validation vulnerability in the Siemens SIMATIC CN 4100 products.

Solid Edge Advisory - This advisory describes three vulnerabilities in the Siemens Solid Edge product.

SINEC Advisory - This advisory describes four vulnerabilities in the Siemens SINEC NMS products.

Updates

IDEC Update - This update provides additional information on the IDEC Products advisory that was originally published on September 19th, 2024.

ECOVACS Update - This update provides additional information on the DEEBOT Vacuum and Base Station advisory that was originally published on May 15th, 2025.

KUNBUS Update - This update provides additional information on the Revolution Pi advisory that was originally published on May 1st, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/10-advisories-and-3-updates-published - subscription required.

Monday, March 10, 2025

Review – Public ICS Disclosures – Week of 3-1-25 – Part 2

For Part 2 we have four additional vendor disclosures from Dell, WAGO, and Weidmueller (2). There are also two updates from Cisco and FortiGuard. We have seven researcher reports for vulnerabilities in products from ABB, Delta Electronics (3), and HP (3). Finally, we have four exploits for products from Advantech (2), ControlID, and HP.

Advisories

Dell Advisory - Dell published an advisory that discusses 64 vulnerabilities in their ThinOS product line.

WAGO Advisory - CERT-VDE published an advisory that describes an unchecked return value vulnerability in multiple WAGO products.

Weidmueller Advisory #1 - CERT-VDE published an advisory that discusses a Sweet32 vulnerability in multiple Weidmueller ethernet switches.

Weidmueller Advisory #2 - CERT-VDE published an advisory that describes a use of hard-coded credentials vulnerability in Weidmueller PROCON-WIN product.

Updates

Cisco Update - Cisco published an update for their small business routers advisory that was originally published on January 11th, 2023, and most recently updated on March 14th, 2023.

FortiGuard Update - FortiGuard published an update for their RADIUS Protocol advisory that was originally published on August 13th, 2024, and most recently updated on January 14th, 2025.

Researcher Reports

ABB Report - Zero Science published a report that describes a security bypass vulnerability (with publicly available exploit) in the ABB Cylon Aspect building energy management program.

Delta Researcher Reports - ZDI published three reports about vulnerabilities in the Delta ISPSoft product.

HP Researcher Reports - ZDI published three reports about vulnerabilities in the HP LaserJet Pro MFP 3301fdw.

Exploits

Advantech Exploit #1 - Indoushka published an exploit for an SQL injection vulnerability in the Advantech WebAccess product.

Advantech Exploit #2 - Indoushka published an exploit for an improper input validation vulnerability in the Advantech DIAEnergie product.

ControlID Exploit - Indoushka published an exploit for an improper authentication vulnerability in the ControlID iDSecure product.

HP Exploit - Indoushka published an exploit for a shell upload vulnerability in the HP Intelligent Management Center.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-a8f - subscription required.

Thursday, September 26, 2024

Review – 5 Advisories Published – 9-26-24

Today, CISA’s NCCIC-ICS published five control system security advisories for products from goTenna (2), Atelmo Atemio, and Advantech (2).

Advisories

goTenna Advisory #1 - This advisory describes nine vulnerabilities in the goTenna Pro ATAK Plugin mesh networking device.

goTenna Advisory #2 - This advisory describes 10 vulnerabilities in the goTenna Pro series mesh networking devices.

Atelmo Advisory - This advisory describes an OS command injection vulnerability (with a publicly available exploit) in the Atelmo Atemio AM 520 HD satellite receiver.

Advantech Advisory #1 - This advisory describes four vulnerabilities in the Advantech ADAM-5630 edge intelligent DAQ controller.

Advantech Advisory #2 - This advisory describes two vulnerabilities in the Advantech ADAM 5550.

 

For more information on these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-published-9-26-24 - subscription required.

Saturday, January 13, 2024

Review – Public ICS Disclosures – Week of 1-6-24 – Part 1

This week we have 12 vendor disclosures from Bosch (2), FortiGuard, GE Gas Power, HPE, Insyde, Palo Alto Networks, SEL, and Splunk (4). We also have three vendor updates from Broadcom, and HP (2). There are three researcher reports for products from X-Rite (2) and Bosch. Finally, we have exploits for products from Advantech and Signalwire.

As is typical for the Saturday after Cyber Tuesday, I will be looking at this week’s advisories and updates from Schneider and Siemens in Part 2.

Advisories

Bosch Advisory #1 - Bosch published an advisory that describes 25 vulnerabilities in their Nexo cordless nutrunner.

Bosch Advisory #2 - Bosch published an advisory that describes an excessive attack surface vulnerability in their BCC Thermostat Product.

FortiGuard Advisory - FortiGuard published an advisory that describes an improper privilege management vulnerability in their FortiOS and FortiProxy products.

GE Gas Power Notice - GE Gas Power published a notice in response to a NERC Section 800 data request to assess the extent of cross-border operation control of Bulk Power System Elements.

HPE Advisory - HPE published an advisory that discusses four vulnerabilities (one of which is listed in CISA’s Known Exploited Vulnerabilities catalog) in their OneView software.

Insyde Advisory - Insyde published an advisory that discusses three vulnerabilities in their UEFI Bios.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses the Terrapin-Attack vulnerability.

SEL Advisory - SEL announced that the latest version (5.2.0.5) of their SEL-5037 SEL Grid Configurator fixes a cybersecurity vulnerability that could allow an authenticated attacker to execute arbitrary code when the computer starts.

Splunk Advisory #1 - Splunk published an advisory that describes an uncontrolled resource consumption vulnerability in their Splunk Enterprise Security product.

Splunk Advisory #2 - Splunk published an advisory that describes an improper input validation vulnerability in their Enterprise Security product.

Splunk Advisory #3 - Splunk published an advisory that discusses seven vulnerabilities in their Enterprise Security.

Splunk Advisory #4 - Splunk published an advisory that discusses six vulnerabilities in their User Behavior Analytics software.

Updates

Broadcom Update - Broadcom published an update for their Netfilter subsystem advisory that was originally published on November 7th, 2023.

HP Update #1 - HP published an update for their Intel Optane SSD Firmware advisory that was originally published on November 20th, 2023.

HP Update #2 - HP published an update for their Intel Rapid Storage Technology advisory that was originally published on November 20th, 2023.

Researcher Reports

X-Rite Reports - Claroty published two reports describing individual vulnerabilities in the X-Rite MA-T6 Kohinoor spectrophotometer firmware.

Bosch Report - Nozomi Networks published a report discussing nine vulnerabilities in the Bosch Rexroth ctrlX HMI WR21 (rebrand of Advantech TPC-110W HMI).

Exploits

Advantech Exploit - Cody 16 published an exploit for an SQL injection vulnerability in the Advantech Web/SCADA.

Signalwire Exploit - Amirhossein Bahramizadeh published an exploit for a race condition vulnerability in the Signalwire FreeSWITCH.

 

For more details on these disclosures, including links to 3rd Party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-9f7 - subscription required.

Saturday, October 21, 2023

Review – Public ICS Disclosures – Week of 10-14-23 – Part 1

This week we have 18 vendor disclosures from Advantech, Aruba Networks, Bosch, Broadcom (3), Cisco (2), Eaton (2), Festo, GE Gas Power, Helmholz, HP (2), HPE, JTEKT, and mb Connect.

Advisories

Advantech Advisory - Advantech published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their R-SeeNet v2 products

Aruba Advisory - Aruba published an advisory that describes an information disclosure vulnerability in their AirWave Management Platform’s web-based management interface.

Bosch Advisory - Bosch published an advisory that describes ‘several vulnerabilities’ in their ctrlX WR21 HMI.

Broadcom Advisory #1 - Broadcom published an advisory that discusses the SOCKS5 heap buffer overflow vulnerability.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an insufficient control flow management vulnerability in their Brocade Extension Switches.

Broadcom Advisory #3 - Broadcom published an advisory that discusses the HTTP2 Rapid Reset vulnerability.

Cisco Advisory #1 - Cisco published an advisory that discusses the SOCKS5 heap buffer overflow vulnerability.

Cisco Advisory #2 - Cisco published an advisory that discusses the HTTP2 Rapid Reset vulnerability.

Eaton Advisory #1 - Eaton published an advisory that describes a weak encoding of passwords vulnerability in their easyE4 product.

Eaton Advisory #2 - Eaton published an advisory that describes a plaintext storage of password vulnerability in their easySoft software.

Festo Advisory - CERT-VDE published an advisory that discusses a path traversal vulnerability in their TP 260 and MES PC products.

GE Gas Power Advisory - GE Gas Power published an advisory that discusses eight vulnerabilities in their NetworkST4, Remote Operations Offering, and M&D Lockbox products.

Helmholz Advisory - CERT-VDE published an advisory that discusses an improper privilege management vulnerability in the Helmholz REX24 products.

HP Advisory #1 - HP published an advisory that describes a privilege escalation vulnerability in multiple products.

HP Advisory #2 - HP published an advisory that discusses 83 vulnerabilities in their HP Device Manager product.

HPE Advisory - HPE published an advisory that describes a denial of service vulnerability in their Integrated Lights-Out product.

JTEKT Advisory - JTEKT published an advisory that describes two vulnerabilities in their OnSinView2 product.

MB Connect Advisory - MB Connect published an advisory that describes an improper privilege management vulnerability in their mymbCONNECT24 and mbCONNECT24 software.

 

For more details about these disclosures, including links to researcher reports and 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-f0f - subscription required.

Thursday, October 12, 2023

Review – 18 Advisories and 1 Updates Published

Today, CISA’s NCCIC-ICS published 16 control system security advisories for products from Schneider, Advantech, Hikvision, Mitsubishi, Weintek, and Siemens (11) and two medical device security advisories for products from Santesoft. They also updated an advisory for products from PTC.

Siemens published one additional advisory (and 11 updates) on Tuesday that were not covered here. CISA no longer updates their Siemens advisories. I will discuss all them this weekend in my Public ICS Disclosure blog post.

Advisories

Schneider Advisory - This advisory describes a missing authentication for critical function vulnerability in the Schneider Interactive Graphical SCADA System (IGSS).

Advantech Advisory - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Advantech WebAccess product.

Hikvision Advisory - This advisory describes two vulnerabilities in the Hikvision Access Control and Intercom Products.

Mitsubishi Advisory - This advisory describes an improper authentication vulnerability in the Mitsubishi MELSEC-F Series main modules.

Weintek Advisory - This advisory describes three vulnerabilities in the Weintek cMT3000 CMI Web CGI.

Mendix Advisory - This advisory describes an observable discrepancy vulnerability in the Siemens Mendix Forgot Password Module.

Tecnomatix Advisory - This advisory describes seven vulnerabilities in the Siemens Tecnomatix Plant Simulation product.

SICAM Advisory #1 - This advisory describes a use of hard-coded credentials vulnerability in the Siemens CP-8050 and CP-8031 master modules.

SICAM Advisory #2 - This advisory describes an incorrect permission assignment for a critical resource vulnerability in the Siemens SICAM PAS/PQS.

SICAM Advisory #3 - This advisory describes a path traversal advisory vulnerability in the Siemens SICAM A8000 CP-8031 and CP-8050 master modules.

SINEC Advisory - This advisory describes two vulnerabilities in the Siemens SINEC NMS.

RUGGEDCOM Advisory - This advisory discusses seven vulnerabilities in the Siemens RUGGEDCOM APE1808.

Simcenter Advisory - This advisory describes a code injection vulnerability in the Siemens Simcenter Amesim product.

Xpedition Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Xpedition Layout Browser.

SCALANCE Advisory - This advisory discusses thirteen vulnerabilities in the Siemens SCALANCE W1750D.

SIMATIC Advisory - This advisory describes two vulnerabilities in the Siemens SIMATIC CP products.

Santesoft Advisory #1 - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante FFT Imaging.

Santesoft Advisory #2 - This advisory describes two vulnerabilities in the Santesoft Sante DICOM Viewer Pro.

Updates

PTC Update - This update provides additional information on an advisory that was originally published on August 31st, 2023.

 

For more information on these advisories, including lists of missing vulnerabilities, links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/18-advisories-and-1-updates-published - subscription required.

Sunday, August 13, 2023

Review – Public ICS Disclosures – Week of 8-5-23 – Part 2

For Part 2 we have a vendor disclosure for products from Schneider. There are also 17 vendor updates from B&R, FortiGuard, Schneider (3) and Siemens (12). Finally, we have 20 researcher reports for products from Advantech, BlueMark, NVIDIA, Softing (11), and Inductive Automation (6).

Advisories

Schneider Advisory - Schneider published an advisory that describes an improper restriction of operations within the bounds of a memory buffer in their Pro-face GP-Pro EX product.

Updates

B&R Update - B&R published an update for their SLP based traffic advisory that was originally published on May 31st, 2023.

FortiGuard Update - FortiGuard published an update for their FortiOS buffer overflow advisory that was originally published on July 28th, 2023.

Schneider Update #1 - Schneider published an update for their EcoStruxure Control Expert advisory that was originally published on January 10th, 2023, and most recently updated on March 14th, 2023.

Schneider Update #2 - Schneider published an update for their EcoStruxure Control Expert advisory that  was originally published on January 10th, 2023, and most recently updated on July 11th, 2023.

Schneider Update #3 - Schneider published an update for their CODESYS Runtime advisory that was originally published on July 11th, 2023.

Siemens Update #1 - Siemens published an update for their Multiple File Parsing advisory that was originally published on May 9th, 2023.

Siemens Update #2 - Siemens published an update for their Authentication Bypass advisory that was originally published on March 14th, 2023 and most recently updated on June 13th, 2023.

Siemens Update #3 - Siemens published an update for their Linux Kernel advisory that was originally published on June 13th, 2023 and most recently updated on July 11th, 2023.

Siemens Update #4 - Siemens published an update for their File Parsing Vulnerabilities advisory that was originally published on July 11th, 2023.

Siemens Update #5 - Siemens published an update for their OPC Foundation advisory that was originally published on April 11th, 2023 and most recently updated on June 13th, 2023.

Siemens Update #6 - Siemens published an update for their IPU 2022.3 Vulnerabilities advisory that was originally published on February 14th, 2023 and most recently updated on July 11th, 2023.

Siemens Update #7 - Siemens published an update for their Missing CSRF Protection advisory that was originally published on November 8th, 2022, and most recently updated on July 11th, 2023.

Siemens Update #8 - Siemens published an update for their additional GNU/Linux subsystem advisory that was originally published on November 27th, 2018 and most recently updated on July 11th, 2023.

Siemens Update #9 - Siemens published an update for their Insyde BIOS Vulnerabilities advisory that was originally published on May 22nd, 2022 and most recently updated on July 11th, 2023.

Siemens Update #10 - Siemens published an update for their SISCO Stack Vulnerability advisory that was originally published on December 13th, 2022 and most recently updated on March 14th, 2023.

Siemens Update #11 - Siemens published an update for their Privilege Management Vulnerability advisory that was originally published on December 13th, 2022. 

Researcher Reports

Advantech Report - CyberDanube published a report that describes two cross-site scripting vulnerabilities in the Advantech EKI-1524-CE series, EKI-1522 series, EKI-1521 series products.

BlueMark Reports - Nozomi Networks published three reports about individual vulnerabilities in the BlueMark DroneScout ds230 Remote ID receiver.

NVIDIA Reports - Cisco TALOS published three reports for individual vulnerabilities in the NVIDIA GPU Display Driver.

Softing Report #1 - ZDI published a report that describes a resource exhaustion vulnerability in the Softing edgeConnector product.

Softing Report #2 - ZDI published a report that describes a directory traversal vulnerability in the Softing Integration Server.

Softing Reports #3-5 - ZDI published three reports of individual vulnerabilities in the Softing edgeAggregator.

Softing Reports #6-9 - ZDI published four reports of individual vulnerabilities in the Softing Secure Integration Server.

Softing Report #10 - ZDI published a report of a NULL pointer dereference vulnerability in the Softing edgeConnector.

Softing Report #11 - ZDI published a report of a hard-coded cryptographic key vulnerability in the Softing Secure Integration Server.

Inductive Automation Reports - ZDI published six reports of vulnerabilities in the Inductive Automation Ignition product.

 

For more details on these disclosures, including a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-1b8 - subscription required.

Saturday, July 29, 2023

Review – Public ICS Disclosure – Week of 7-22-23

This week we have 21 vendor disclosures from ABB (2), Aruba Networking, Belden (3), Bosch, Brocade (2), B&R, CODESYS, Fujitsu (3), Hitachi Energy (2), Honeywell, HPE, QNAP (2), and VMware. There is one researcher report for vulnerabilities in products from Advantech. Finally, we have two exploits for products from Western Digital and VMware.

Advisories

ABB Advisory #1 - ABB published an advisory that describes four vulnerabilities in their Ability™ zenon product.

ABB Advisory #2 - ABB published an advisory that describes an unquoted search path vulnerability in their AO-OPC product.

Aruba Advisory - Aruba published an advisory that describes four vulnerabilities in their Access Points products

Belden Advisory #1 - Belden published an advisory that discusses a NULL pointer dereference vulnerability in their Hirschmann HiSecOS.

Belden Advisory #2 - Belden published an advisory that discusses a cross-site scripting vulnerability in their Eagle firewall products.

Belden Advisory #3 - Belden published an advisory that discusses four vulnerabilities in their Hirschmann HiSecOS.

Bosch Advisory - Bosch published an advisory that discusses 30 vulnerabilities in their PRA-ES8P2S Ethernet-Switchs.

Broadcom Advisory #1 - Broadcom published an advisory that discusses a permission validation vulnerability in the BrocadeOS products.

Broadcom Advisory #2 - Broadcom published an advisory that discusses the MoveIT SQL injection vulnerability, which is on the CISA Known Exploited Vulnerabilities Catalog.

B&R Advisory - B&R published an advisory that describes an allocation of resources without limit or throttling vulnerability in the Portmapper service used in their Automation Runtime product.

CODESYS Advisory - CODESYS published an advisory that describes an exposure of resource to wrong sphere vulnerability in their Scripting addon.

Fujitsu Advisory #1 - Fujitsu published a notice about potential vulnerabilities being investigated based upon third-party advisories from Insyde.

Fujitsu Advisory #2 - JP CERT published an advisory that describes an authentication bypass vulnerability in the Fujitsu Si-R series and SR-M series network devices.

Fujitsu Advisory #3 - JP CERT published an advisory that describes a hard-coded credentials vulnerability in the Fujitsu IP Series Real-time Video Transmission Gear.

Hitachi Energy Advisory #1 - Hitachi published an advisory that discusses six vulnerabilities in their AFF66x Products. These are third-party vulnerabilities.

Hitachi Energy Advisory #2 - Hitachi published an advisory that describes two classic buffer overflow vulnerabilities in their RTU500 series product.

Honeywell Advisory - Honeywell published an end-of-life notice for their MAXPRO® VMS R600 and R630 / NVR6.0 & R6.3 products.

HPE Advisory - HPE published an advisory that describes a privilege escalation vulnerability in their Integrated Smart Update Tools (iSUT) for Windows.

QNAP Advisory #1 - QNAP published an advisory that discusses an OS command injection vulnerability in many of their products.

QNAP Advisory #2 - QNAP published an advisory that describes an insecure library loading vulnerability in their QVPN Device Client for Windows.

VMware Advisory - VMware published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Tanzu Application Service for VMs.

Reports

Advantech Report - Tenable published a report that describes an SQL injection vulnerability in the Advantech iView.

Exploits

Western Digital Exploit - Remco Vermeulen published a Metasploit module for two vulnerabilities in the Western Digital MyCloud product.

VMware Exploit - H00die published a Metasploit module for a command injection vulnerability in the VMware Aria Operations for Networks product.

Thursday, June 22, 2023

Review – 2 Advisories and 2 Updates Published – 6-22-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from SpiderControl and Advantech. They also updated two advisories for products from Mitsubishi and Econolite.

Advisories

SpiderControl Advisory - This advisory describes a path traversal vulnerability in the SpiderControl SCADA Webserver.

Advantech Advisory - This advisory describes two vulnerabilities in the Advantech R-SeeNet server monitors.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on March 2nd, 2023.

Econolite Update - This update provides additional information on an advisory that was originally published on January 26th, 2023.

 

For more details on these advisories, including a discussion about a missing advisory number, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-2-updates-published-c3d - subscription required.

Friday, June 16, 2023

Review – 14 Advisories Published – 6-15-23

 Yesterday, CISA’s NCCIC-ICS published 14 control system security advisories for products from Siemens (12), Advantech, and SUBNET Solutions.

NOTE: Siemens also updated eight advisories this week, but a policy change at CISA in January means that those Siemens updates are no longer being reported by NCCIC-ICS. I will be covering them this weekend.

Advisories

Teamcenter Advisory - This advisory describes four vulnerabilities in the Siemens JT2Go and Teamcenter Visualization products.

SICAM Advisory #1 - This advisory describes three vulnerabilities in the Siemens SICAM A8000 Devices. The vulnerabilities were reported by the SEC Consult Lab.

SICAM Advisory #2 - This advisory describes six vulnerabilities in the Siemens POWER METER SICAM Q200 family.

SINAMICS Advisory - This advisory discusses 23 vulnerabilities in the Siemens SINAMICS MV (medium voltage) products.

SIMATIC Advisory #1 - This advisory discusses 108 vulnerabilities in the Siemens SIMATIC S7-1500 TM MFP.

SIMATIC Advisory #2 - This advisory discusses 53 vulnerabilities in the BIOS of the Siemens SIMATIC S7-1500 TM MFP.

SIMATIC Advisory #3 - This advisory describes a code injection vulnerability in the Siemens SIMATIC PCS 7, SIMATIC S7-PM, and SIMATIC STEP 7 V5 products.

SIMATIC Advisory #4 - This advisory describes an incorrect permission assignment for critical resource vulnerability in the Siemens SIMATIC WinCC.

SIMATIC Advisory #5 - This advisory describes a use of obsolete function (legacy OPC services) vulnerability in the Siemens SIMATIC products.

Solid Edge Advisory - This advisory describes an out-of-bounds read vulnerability in the Siemens Solid Edge SE2023 product.

TIA Portal Advisory - This advisory describes a protection mechanism failure vulnerability in the Siemens TIA Portal.

SIMOTION Advisory - This advisory describes an exposure of sensitive information due to incompatible policies vulnerable in the Siemens SIMOTION products.

Advantech Advisory - This advisory describes an untrusted pointer dereference vulnerability in the Advantech WebAccess/SCADA product.

SUBNET Advisory - This advisory describes two vulnerabilities in the SUBNET PowerSYSTEM Center.

Commentary

While Siemens reported an apparently egregious number of vulnerabilities (108 and 53 in separate advisories) in their SINAMICS medium voltage products, these are all Linux vulnerabilities and Siemens has been cumulatively reporting similar slow-to-be-fixed Linux vulnerabilities in their SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP since 2018. This is one of the problems with using a general-purpose OS for control system products. If Siemens was reporting Windows vulnerabilities, I am sure that we would be seeing a large number of such advisories being published every month. Most vendors do not report Windows related vulnerabilities because, where their products use that OS, they rely on Microsoft’s automated update service to relatively painlessly fix those problems. Interestingly, that means those products are exposed to the Internet for that service to work.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-advisories-published-6-15-23 - subscription required.

Thursday, June 1, 2023

Review – 2 Advisories and 3 Updates Published – 6-1-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from HID Global and Advantech. They also updated three advisories for products from Hitachi Energy, Mitsubishi Electric, and Delta Electronics.

Advisories

HID Advisory - This advisory describes a modification of assumed mutable data in the HID SAFE using the optional External Visitor Manager portal.

Advantech Advisory - This advisory describes three vulnerabilities in the Advantech WebAccess/SCADA product.

Updates

Hitachi Update - This update provides additional information on an advisory that was originally published on April 6th, 2021 and most recently updated on April 20th, 2021.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on November 29th, 2022.

Delta Update - This update provides additional information on an advisory that was originally published on September 13th, 2022 (not 9-19-22).

 

For more details about these advisories, including a brief discussion about CISA’s disclosure of vulnerabilities found inhouse – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-3-updates-published - subscription required.

Tuesday, May 30, 2023

Review - 1 Advisory Published – 5-30-23

Today, CISA’s NCCIC-ICS published a new control system security advisory for products from Advantech.

Advisories

Advantech Advisory - This advisory describes an insufficient type-distinction vulnerability in the Advantech WebAccess/SCADA product.

Sunday, May 14, 2023

Review – Public ICS Disclosures – Week of 5-6-23 – Part 2

For Part 2 this week we have four additional vendor disclosures from Schneider. We also have 18 updates for products from Schneider (2) and Siemens (16). There are three researcher reports for products from Advantech and Weston (2).

Advisories

Schneider Advisory #1 - Schneider published an advisory that describes an improper XML external entity reference vulnerability in their OPC Factory Server.

Schneider Advisory #2 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power Operation, EcoStruxure Power SCADA Operation products.

Schneider Advisory #3 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power Operation, EcoStruxure Power SCADA Operation products.

Schneider Advisory #4 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power SCADA Anywhere products.

Updates

Schneider Update #1 - Schneider published an update for their INFRA:HALT advisory that was originally published on February 8th, 2022, and most recently updated on February 14th, 2023.

Schneider Update #2 - Schneider published an update for their BadAlloc advisory that was originally published on April 12th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #1 - Siemens published an update for their SIPROTEC 5 devices advisory that was originally published on April 11th, 2023.

Siemens Update #2 - Siemens published an update for their Siemens Industrial Products using Intel CPUs advisory that was originally published on August 10th, 2021 and most recently updated on December 13th, 2022.

Siemens Update #3 - Siemens published an update for their TIA Portal advisory that was originally published on April 11th, 2023.

Siemens Update #4 - Siemens published an update for their SIMATIC S7-400 CPUs advisory that was originally published on November 13th, 2018 and most recently updated on January 10th, 2023.

Siemens Update #5 - Siemens published an update for their OpenSSL Affecting Industrial Products advisory that was originally published on June 14th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #6 - Siemens published an update for their Siemens Industrial Products using Intel CPUs advisory that was originally published on February 14th, 2023.

Siemens Update #7 - Siemens published an update for their TIA Project-Server advisory that was originally published on February 14th, 2023.

Siemens Update #8 - Siemens published an update for their Polarion ALM advisory that was originally published on April 11th, 2014.

Siemens Update #9 - Siemens published an update for their Industrial Products advisory that was originally published on March 20th, 2018 and most recently updated on April 11th, 2023.

Siemens Update #10 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 11th, 2023.

Siemens Update #11 - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022.

Siemens Update #12 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 9th, 2019.

Siemens Update #13 - Siemens published an update for their e Web Server Login Page of Industrial Controllers advisory that was originally published on November 8th, 2022 and most recently updated on April 11th, 2023.

Siemens Update #14 - Siemens published an update for their Profinet Devices advisory that was originally published on October 8th, 2018, and most recently update on January 10th, 2023.

Siemens Update #15 - Siemens published an update for their Industrial Products advisory that was originally published on December 13th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #16 - Siemens published an update for their n Industrial Real-Time (IRT) Devices advisory that was originally published on October 8th, 2019, and most recently updated on April 11th, 2023.

Researcher Reports

Advantech Report - Cyber Danube published a report about three vulnerabilities in the Advantech EKI-1524-CE series, EKI-1522 series, EKI-1521 series serial device servers.

Weston Reports - Cisco Talos published two reports about three vulnerabilities in the Weston Embedded uC-FTPs.

 

For more details on these disclosures, including a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-e8f - subscription required.

 
/* Use this with templates/template-twocol.html */