Showing posts with label Arista. Show all posts
Showing posts with label Arista. Show all posts

Saturday, June 20, 2026

Review – Public ICS Disclosures – 6-13-26 – Part 1

This is a moderately busy disclosure week.  For Part 1 we have 11 vendor disclosures from Arista, Belden, Dell (2), Dassault, Genetec, HP (2), HPE (2), and iba. 

Advisories  

Arista Advisory - Arista published an advisory that discusses the AirSnitch attacks. 

Belden Advisory - Belden published an advisory that describes a download of code without integrity check vulnerability in their Hirschmann Rail Data Diode. 

Dell Advisory #1 - Dell published an advisory that discusses three vulnerabilities in their Wyse Management Suite. 

Dell Advisory #2 - Dell published an advisory that describes two vulnerabilities in their Wyse Management Suite. 

Dassault Advisory - Dassault published an advisory that describes a path traversal vulnerability in their SOLIDWORKS Visualize product. 

NOTE: Dassault only provides access to advisories to registered owners. 

Genetec Advisory - Genetec published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Security Center systems main server installations. 

HP Advisory #1 - HP published an advisory that discusses an insufficient granularity of access control vulnerability in their business notebook and desktop PCs. 

HP Advisory #2 - HP published an advisory that discusses three vulnerabilities in their One Agent Software Bundled with HP Privacy Settings. 

HPE Advisory #1 - HPE published an advisory that discusses an improper initialization vulnerability in their SimpliVity Servers. 

HPE Advisory #2 - HPE published an advisory that discusses an improper access control for register interface vulnerability in their SimpliVity AMD Servers. 

Iba Advisory - CERT-VDE published an advisory that describes a deserialization of untrusted data vulnerabilities in the iba ibaDatCoordinator and ibaPDA products. 


For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-6-13-26-part - subscription required. 

Tuesday, June 9, 2026

CISA Adds Arista Vulnerability to KEV Catalog – 6-9-26

Today, CISA announced that it had added an incomplete comparison with missing factors vulnerability in the Arista EOS to CISA’s Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was previously disclosed by Arista and was originally reported by Scott Christiansen, Lukas Peitz, Rich Compton, and Jonathan Davis at Comcast. In version 1.1 (May 6th) of their advisory, Arista reported that the vulnerability had been reported as being exploited in the wild. Arista provides settings to mitigate the vulnerability; no software fix is planned. 

CISA is requiring federal agencies to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. A deadline of June 23rd2026, has been set. 

Saturday, June 6, 2026

Review – Public ICS Disclosures – Week of May 30th, 2026 – Part 1

This week we have a moderately busy disclosure week. For Part 1 there are 12 vendor disclosures from Arista, Dassault Sytems (2), D-Link, Eaton, HP, HPE (2), MBS, NI, Phillips, and Phoenix Contact. 

Advisories  

Arista Advisory Arista published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability (with publicly available exploit) in their EOS platform products. 

Dassault Advisory #1 - Dassault published an advisory that describes a cross-site scripting vulnerabbility in their Process Experience Studio in DELMIA Service Process Engineer. 

Dassault Advisory #2 - Dassault published an advisory that describes a deserialization of untrusted data vulnerability in their Teamwork Cloud from No Magic product. 

D-Link Advisory D-Link published an advisory that describes a use of weak credentials vulnerability in their DWR-X1820 router. 

Eaton Advisory - Eaton published an advisory that discusses a TOCTOU race condition vulnerabiltiy in their ProView NXG application software. 

HP Advisory - HP published an advisory that describes a stack-based buffer overflow vulnerability (with publicly available exploit) in their Poly Voice products. 

HPE Advisory #1 HPE published an advisory that discusses ten vulnerabilities (four with publicly available exploits) in their Telco Network Function Virtualization Orchestrator. 

HPE Advisory #2 - HPE published an advisory that discusses a TOCTOU race condition vulnerability in their ArubaOS-CX Switches. 

MBS Advisory - CERT-VDE published an advisory that describes 11 vulnerabilities in the MBS Universal Gateways (UGW-A-Series, UGW-X-Series) used in multiple MBS products.3 

NI Advisory NI published an advisory that describes two vulnerabilities in their NI-PAL product. 

Philips Advisory - Philips published an advisory that discusses the Windows’ BlueHammer, RedSun, and UnDefend vulnerabilities. 

Phoenix Contact Advisory Phoenix Contact published an advisory that describs an exposure of sensitive information to an unauthorized actor vulnerability in their CHARX SEC-3150 product. 


For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-may - subscription required. 

 
/* Use this with templates/template-twocol.html */