Showing posts with label BD. Show all posts
Showing posts with label BD. Show all posts

Tuesday, January 28, 2025

Review – 6 Advisories and 1 Update Published – 1-28-25

Today CISA’s NCCIC-ICS published six control system security advisories for products from Schneider Electric (2), Rockwell Automation (3), and B&R. They also updated a medical device advisory for products from BD.

Three additional Rockwell advisories were published today. If they are not covered in CISA advisories on Thursday, I will discuss them this weekend in my Public ICS Disclosures post.

Advisories

Schneider Advisory #1 - This advisory describes a deserialization of untrusted data vulnerability in the Schneider Electric RemoteConnect and SCADAPack x70 Utilities.

Schneider Advisory #2 - This advisory describes two vulnerabilities in the Schneider PowerLogic HDPM6000 High-Density Metering System.

Rockwell Advisory #1 - This advisory describes two vulnerabilities in the Rockwell DataMosaix Private Cloud.

Rockwell Advisory #2 - This advisory describes two vulnerabilities in the Rockwell FactoryTalk product.

Rockwell Advisory #3 - This advisory describes two vulnerabilities in the Rockwell FactoryTalk View ME product.

B&R Advisory - This advisory describes the use of a broken or risky cryptographic algorithm vulnerability in the B&R Automation Runtime and mapp View products.

Updates

BD Update - This update provides additional information on the BD Diagnostic Solutions Products advisory that was originally published on December 17th, 2024.

 

For more information about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-286 - subscription required.

Tuesday, December 17, 2024

Review – 5 Advisories Published – 12-17-24

Today CISA’s NCCIC-ICS published four control system security advisories for products from Schneider Electric, Rockwell Automation, Hitachi Energy, and ThreatQuotient. They also published a medical device security advisory for products from BD.

Advisories

Schneider Advisory - This advisory describes an improper input validation vulnerability in the Schneider Modicon PLCs.

Hitachi Energy Advisory - This advisory discusses an improper input validation vulnerability in the Hitachi Energy TropOS devices.

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell PowerMonitor 1000 Remote products.

ThreatQuotient Advisory - This advisory describes a command injection vulnerability in the ThreatQuotient ThreatQ Platform.

BD Advisory - This advisory describes a use of default credentials vulnerability in multiple BD Diagnostic Solutions products.

 

For more information on these vulnerabilities, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-published-12-17-24 - subscription required.

Saturday, July 20, 2024

Review – Public ICS Disclosures – Week of 7-13-24

This week we have three vendor disclosures on the regreSSHion vulnerability from Bosch, Broadcom, HMS  We have 14 additional vendor disclosures from ABB, Dell, Fujitsu, Hitachi, HP (4), HPE (3), Rockwell (2), and Wireshark. There are also five vendor updates from BD and HPE (4). Finally, we have four researcher reports about vulnerabilities in products from Asus, Synology, and Unitronics (2).

RegreSSHion Advisories

Bosch published an advisory that lists affected products and fixed versions.

Broadcom published an advisory that lists the products that are not affected.

HMS published an advisory that lists the affected products and announces that fixes have been applied.

Advisories

ABB Advisory - ABB published an advisory that describes an unquoted search path or element vulnerability in their Mint Workbench product.

Dell Advisory - Dell published an advisory that lists a large number (nope, I am not counting them all) of 3rd party vulnerabilities in their ThinOS product.

Fujitsu Advisory - JP-CERT published an advisory that describes a path traversal vulnerability in the Fujitsu Network Edgiot GW1500 product.

Hitachi Advisory - Hitachi published an advisory that discusses 42 vulnerabilities in their Disc Array Systems products.

HP Advisory #1 - HP published an advisory that describes a buffer overflow vulnerability in multiple desk top computers.

HP Advisory #2 - HP published an advisory that describes two privilege escalation vulnerabilities in their display control software.

NOTE: The HP Security Bulletins page lists two additional advisories (here and here), but neither page currently opens.

HPE Advisory #1 - HPE published an advisory that describes a remote bypass of a security restriction vulnerability in their 3PAR Service Processor Software.

HPE Advisory #2 - HPE published an advisory that discusses 17 vulnerabilities (one with known exploits) in their Unified OSS Console Assurance Monitoring (UOCAM) product.

HPE Advisory #3 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML/XL, Synergy, Edgeline and Alletra Servers.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their SequenceManager Server.

Advisory #2 - Rockwell published an advisory that describes an improper input validation vulnerability in their 5015 – AENFTXT product.

Wireshark Advisory - Wireshark published an advisory that describes a packet injection vulnerability in their SPRT dissector product.

Updates

BD Update - BD published an update for their Third-Party ESET advisory that was originally published on March 29th, 2024.

HPE Update #1 - HPE published an update for their Intel Thunderbolt Driver advisory that was originally published on May 14th, 2024 and most recently updated on June 17th, 2024.

HPE Update #2 - HPE published an update for their Intel PROSet/Wireless WiFi and Bluetooth advisory that was originally published on May 14th, 2024 and most recently updated on June 17th, 2024.

HPE Update #3 - HPE published an update for their Intel Chipset Device Software advisory that was originally published on June 28th, 2024.

HPE Update #4 - HPE published an update for their Intel 2024.1 IPU - Chipset Software advisory that was originally published on March 13th, 2024 and most recently updated on April 10th, 2024.

Researcher Reports

Asus Report - BugProve published a report describing a stack-based buffer overflow vulnerability in the Asus RT-AC87U router.

Synology Report - Claroty published a report that describes a classic buffer overflow vulnerability in the Synology BC 500 IP camera.

Unitronics Reports - Claroty published two reports about individual vulnerabilities in the Unitronics Vision Plc.

 

For more information about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-3e2 - subscription required.

Saturday, July 13, 2024

Review – Public ICS Disclosures – Week of 7-6-23 – Part 1

This week we have eight vendor disclosures about the Blast-Radius and RegreSSHion vulnerabilities. We have 25 additional vendor disclosures from BD, FortiGuard (3), Hitachi, Moxa, OPC Foundation, Palo Alto Networks (5), Pepperly+Fuchs (2), Philips, Schneider (4), SEL, and VMware (7).

Blast-RADIUS Advisories

Cisco published an advisory that provides a list of products currently under review as being potentially affected.

HPE published an advisory that provides a list of Aruba Networking products affected.

Palo Alto Networks published an advisory that provides a list of affected products and provides work arounds.

WatchGuard published an advisory that provides a list of products that they are investigating with regards to this vulnerability.

RegreSSHion Advisories

Cisco published an update that updated the lists of affected products, unaffected products, and products currently under review.

HMS published an advisory that provides a list of affected products and reports that: “All servers have been updated on 10/07/2024. No further actions are needed.”

Philips published an advisory that reports that none of their products are affected.

Synology published an advisory that reports that none of their products are affected.

Advisories

BD Advisory - BD published an advisory that discusses an improper privilege management vulnerability in multiple BD products.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiExtender authentication component.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an incorrect parsing of numbers with different radices vulnerability in their FortiOS and FortiProxy IP address validation feature.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiOS and FortiProxy's web SSL VPN UI.

Hitachi Advisory - Hitachi published an advisory that discuses 70 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities.

Moxa Advisory - Moxa published an advisory that discusses a use after free vulnerability (that is listed in CISA’s Known Exploited Vulnerabilities Catalog) in multiple Moxa products.

OPC Foundation - The OPC Foundation published an advisory that describes an allocation of resources without limits or throttling vulnerability in their UA-.NETStandard product.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a hard-coded password vulnerability in their Expedition VM product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes an improper input validation vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an improper verification of cryptographic signature vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes a missing authentication for critical function vulnerability in the Network Expedition product.

Pepperl+Fuchs Advisory #1 - CERT-VDE published an advisory that discusses a use after free vulnerability in their Smart-Ex 02 and Smart-Ex 03 products.

Pepperl+Fuchs Advisory #2 - CERT-VDE published an advisory that describes two vulnerabilities in the Pepperl+Fuchs OIT-XXXX products.

Philips Advisory - Philips published an advisory that discusses a TeamViewer vulnerability. Philips reports that none of their products are affected.

Schneider Advisory #1 - Schneider published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their Wiser Home Controller WHC-5918A.

Schneider Advisory #2 - Schneider published an advisory that describes three vulnerabilities in their Foxboro DCS Core Control Services.

Schneider Advisory #3 - Schneider published an advisory that describes a path traversal vulnerability in their EcoStruxure Foxboro SCADA FoxRTU Station.

Schneider Advisory #4 - Schneider published an advisory that describes a cross-site scripting vulnerability in their Modicon Controllers.

SEL Advisory - SEL published a new version notice for their SEL-5052 Server Software that includes descriptions of cybersecurity fixes.

VMware Advisory #1 - Broadcom published an advisory that describes an SQL injection vulnerability in the VMware Aria Automation product.

VMware Advisories #2 thru #7 - Broadcom re-published six VMware advisories in the Broadcom format.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-c55 - subscription required.

Saturday, April 6, 2024

Review – Public ICS Disclosures – Week of 3-30-24

This week we have five vendor disclosures about the XZ Utils vulnerability from Broadcom, Palo Alto Networks, Philips, QNAP, and WatchGuard. We have fourteen additional vendor disclosures from ABB, BD, Broadcom (2), Cisco, Hikvision, HP, HPE (4), Palo Alto Networks, Philips, and VMWare. There are four vendor updates from Eaton, HP (2), and HPE. We have five researcher reports for vulnerabilities in products from Open Automation Software (4) and Positron. Finally, we have an exploit for products from Petrol Pump.

XZ Utils Advisories

Broadcom published an advisory that discussed the XZ Utils vulnerability.

Palo Alto Networks published an advisory that discussed the XZ Utils vulnerability.

Philips published an advisory that discussed the XZ Utils vulnerability.

QNAP published an advisory that discussed the XZ Utils vulnerability.

WatchGuard published an advisory that discussed the XZ Utils vulnerability.

Advisories

ABB Advisory - ABB published an advisory that describes an improper input validation vulnerability in the Virtual PNI API in their S+ Engineering product.

BD Advisory - BD published an advisory that discusses an improper privilege management vulnerability in a number of their products.

Broadcom Advisory #1 - Broadcom published an advisory that describes an OS command injection vulnerability in their Brocade Fabric OS product.

Broadcom Advisory #2 - Broadcom published an advisory that describes an origin validation error vulnerability in their Brocade Fabric OS product.

Cisco Advisory - Cisco published an advisory that describes two vulnerabilities in their Emergency Responder product.

Hikvision Advisory - Hikvision published an advisory that describes three vulnerabilities in their NVR devices.

HP Advisory - HP published an advisory that describes an improper access control vulnerability in their CCX devices.

HPE Advisory #1 - HPE published an advisory that discusses eight vulnerabilities (three with known exploits) in their Unified OSS Console Assurance Monitoring product.

HPE Advisory #2 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/ML/SY/RL/XL/Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that describes a privilege escalation vulnerability in their MSA SAN Storage VSS Provider and CAPI Proxy Software.

HPE Advisory #4 - HPE published an advisory that describes an unauthorized access to files vulnerability in their NonStop Web ViewPoint Enterprise software.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses eight third-party vulnerabilities that could be associated with their Prisma SD-WAN ION product.

Philips Advisory - Philips published an advisory that discusses a use-after-free vulnerability in multiple Philips products.

VMware Advisory - VMware published an advisory that describes three vulnerabilities in their SD-WAN Edge and SD-WAN Orchestrator products.

Updates

Eaton Update - Eaton published an update for their Apache Log4j advisory that was originally published on December 14th, 2021 and most recently updated on January 31st, 2022.

HP Update #1 - HP published an update for their OfficeJet Pro advisory that was originally published on March 20th, 2024.

HP Update #2 - HP published an update for their AMD Graphics Driver advisory that was originally published on November 21st, 2023.

HPE Update - HPE published an update for their SimpliVity Servers advisory that was originally published on February 15th, 2024.

Researcher Reports

Open Automation Software Reports - Talos published four reports for individual vulnerabilities in the OAS Platform product.

Positron Report - Zero Science published a report about an authentication bypass vulnerability in the Positron TRA7005 series broadcast signal processor.

Exploits

Petrol Pump Exploit - Sandeep Vishwakarma published an exploit for a file upload vulnerability in the Petrol Pump Management software.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-671 - subscription required. 

Saturday, December 16, 2023

Review – Public ICS Disclosures – Week of 12-9-23 – Part 1 –

This week we have 22 vendor disclosures from ABB, Beckhoff, BD (2), Bosch (2), Cisco, FortiGuard (3), Frauscher, HPE (3), JTEKT, and Palo Alto Networks (7).

Advisories

ABB Advisory - ABB published an advisory that discusses the Apache ActiveMQ deserialization of untrusted data vulnerability that is listed on the CISA Known Exploited Vulnerabilities Catalog.

Beckhoff Advisory – CERT-VDE published an advisory that describes an open redirect vulnerability in the Beckhoff TwinCAT/BSD product.

BD Advisory #1 - BD published an advisory that discusses the Windows 7 Operating System End of Life Notice.

BD Advisory #2 - BD published an advisory that discusses an out-of-bounds write vulnerability that is listed in the CISA KEV catalog.

Bosch Advisory #1 - Bosch published an advisory that describes two improper handling of a malformed API request vulnerabilities in their BT software products

Bosch Advisory #2 - Bosch published an advisory that describes a command injection vulnerability in their Bosch IP Cameras.

Cisco Advisory - Cisco published an advisory that discusses the recent Apache Struts vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a use of externally controlled format string vulnerability in their FortiOS, FortiProxy and FortiPAM products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a double free vulnerability in their FortiOS and FortiPAM HTTPSd daemon.

Frauscher Advisory - CERT-VDE published an advisory that describes a code injection vulnerability in the Frauscher FDS102 for FAdC/FAdCi.

HPE Advisory #1 - HPE published an advisory that discusses seven vulnerabilities in their Cray Programming Environment.

HPE Advisory #2 - HPE published an advisory that discusses six vulnerabilities in their Intelligent Management Center (iMC) product.

HPE Advisory #3 - HPE published an advisory that discusses 14 vulnerabilities in their Virtualized Telecommunication Management Information Platform (vTeMIP) application.

JTEKT Advisory - JTEKT published an advisory that describes four uncontrolled resource consumption vulnerabilities in their HMI GC-A2 series products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a weakness introduced during design vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an argument injection vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes an OS command injection vulnerability in their PAS-OS product.

Palo Alto Networks Advisory #6 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their PAN-OS product.

Palo Alto Networks Adviosry #7 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS product.

 

For more details about these disclosures, including links to 3rd party advisories, vendor advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-9fa https://tinyurl.com/yty8yuyt- subscription required. 

Tuesday, November 28, 2023

Review – 4 Advisories Published – 11-28-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Mitsubishi Electric, Franklin Electric Fueling Systems, and Delta Electronics. They also published a medical device security advisory for products from BD.

Advisories

Mitsubishi Advisory - This advisory describes two improper input validation vulnerabilities in the Mitsubishi GX Works2.

Franklin Advisory - This advisory describes a path traversal vulnerability in the Franklin FFS Colibri fuel inventory monitoring system.

Delta Advisory - This advisory describes four vulnerabilities in the Delta InfraSuite Device Master product.

BD Advisory - This advisory describes seven vulnerabilities in the BD BD FACSChorus workstations.

 

For more details about these advisories, including corrected link for vendor advisory, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-published-11-28-23 - subscription required.

Saturday, October 28, 2023

Review – Public ICS Disclosures – Week of 10-21-23

This week we have eight vendor disclosures from Aruba Networks, Bosch, Festo, Genetec, HP, Omron, Sick, and VMware. There are eight vendor updates from BD (2), Cisco (3), HP, and HPE (2). There are two researcher reports for vulnerabilities in products from TEM. Finally, we have two exploits for products from Splunk and VMware.

Advisories

Aruba Advisory - Aruba published an advisory that describes five vulnerabilities in their ClearPass Policy Manager.

Bosch Advisory - Bosch published an advisory that discusses an authentication bypass by capture replay vulnerability in their Rexroth SLC-0-GPNT00300 product.

Festo Advisory - CERT-VDE published an advisory that discusses an improper input validation vulnerability in the Festo TP 260 and MES PC products.

Genetec Advisory - Genetec published an advisory that discusses a command injection vulnerability in their Genetec A1610 and A1210 network door controllers.

HPE Advisory - HPE published an advisory that describes a remote code execution vulnerability in their OneView product.

Omron Advisory - Omron published an advisory that describes a restriction of XML external entity reference vulnerability in their CX Designer product.

Sick Advisory - Sick published an advisory that describes an authentication bypass by capture-replay vulnerability in their Flexi Soft Gateways.

VMware Advisory #1 - VMware published an advisory that describes two vulnerabilities in their vCenter Server.

VMware Advisory #2 - VMware published an advisory that describes two vulnerabilities in their Tools product.

Updates

BD Update #1 - BD published an update for their Busy Box advisory.

BD Update #2 - BD published an update for their Linux Kernel Vulnerability within Wi-Fi Module in Alaris PCU advisory.

Cisco Update #1 - Cisco published an update for their IOS XE Software Web UI Command Injection advisory that was originally published on March 24th, 2021.

Cisco Update #2 - Cisco published an update for their HTTP/2 Rapid Reset Attack advisory that was originally published on October 16th, 2023.

Cisco Update #3 - Cisco published an update for their IOS XE Software Web UI Feature Attack advisory that was originally published on October 16th, 2023.

HP Update - HP published an update for their NVIDIA GPU Display Driver that was originally published on September 11th, 2023.

HPE Update #1 - HPE published an update for their Aruba AirWave Management Platform advisory that was originally published on October 17th, 2023.

HPE Update #2 - HPE published an update for their NonStop advisory that was originally published on July 18th, 2022 and most recently updated on March 30th, 2023.

Researcher Reports

TEM Reports - Zero Science published two reports of individual vulnerabilities in the TEM Opera Plus FM Family Transmitter.

Exploits

Splunk Exploit - Heyder Andrade published a Metasploit module for a privilege escalation vulnerability in Splunk.

VMware Exploit - SinSinology published an exploit for a use of broken or risky cryptographic algorithm vulnerability in the VMware Aria Operations for Networks program.

 

For more details about these disclosures, including links to 3rd party advisories and researcher reports as well as brief update summaries, see my article at CFSN Detailed analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-19b - subscription required. 

Thursday, October 26, 2023

Review – 8 Advisories and 1 Update Published – 10-26-23

Today, CISA’s NCCIC-ICS published eight control system security advisories for products from Sielco, Rockwell Automation, Ashlar-Vellum, Centralite, and Dingtian. They also updated a medical device security advisory for products from BD Alaris.

Advisories

Sielco Advisory #1 - This advisory describes four vulnerabilities in the Sielco Analog FM Transmitters and Radio Link.

Sielco Advisory #2 - This advisory describes seven vulnerabilities in the Sielco PolyEco FM transmitters.

Rockwell Advisory #1 - This advisory describes an improper authentication vulnerability in the Rockwell FactoryTalk Services Platform web service.

Rockwell Advisory #2 - This advisory describes an improper input validation vulnerability in the Rockwell FactoryTalk View Site Edition.

Rockwell Advisory #3 - This advisory describes two vulnerabilities in the Rockwell Arena simulation software.

Ashlar-Vellum Advisory - This advisory describes two vulnerabilities in the Ashlar-Vellum Cobalt, Graphite, Xenon, Argon, Lithium, and Cobalt Share modeling programs.

Centralite Advisory - This advisory describes an allocation of resources without limits or throttling vulnerability in the Centralite Pearl Thermostat.

Dingtian Advisory - This advisory describes an authentication bypass by capture relay vulnerability in the Dingtian DT-R002 relay.

Updates

BD Alaris Update - This update provides additional information on an advisory that was originally published on July 13th, 2023.

 

For more information on these advisories, including links to researcher advisories, and a down-the-rabbit-hole look at one of the Rockwell advisories - https://patrickcoyle.substack.com/p/8-advisories-and-1-update-published - subscription required.

 

Saturday, August 5, 2023

Review – Public ICS Disclosures – Week of 7-29-23 – Part 1 -

This week in Part 1 we have 80 vendor advisories from Aruba Networks, BD, Broadcom (45), CODESYS (5), Fujitsu, GE Gas Power, HP, HPE, Omron (3), Schweitzer Engineering Laboratory, Setelsa Security, Splunk, Tanzu (16), WAGO (2), and VMware.

For Part 2 I will look at vendor updates and researcher reports.

Advisories

Aruba Advisory - Aruba published an advisory that describes a command injection vulnerability in their CX Switches.

BD Advisory - BD published an advisory that discusses an incorrect authorization vulnerability in multiple products.

Broadcom Advisories - Broadcom published 45 advisories for third-party vulnerabilities in a variety of their products.

CODESYS Advisory #1 - CODESYS published an advisory that describes an improper restriction of excessive authentication attempts vulnerability in their Development System product.

CODESYS Advisory #2 - CODESYS published an advisory that describes an insufficient verification of data authenticity vulnerability in their Development System product.

CODESYS Advisory #3 - CODESYS published an advisory that describes an uncontrolled search path vulnerability in their Development System product.

CODESYS Advisory #4 - CODESYS published an advisory that describes 15 vulnerabilities in their Control V3 runtime systems products.

CODESYS Advisory #5 - CODESYS published an advisory that describes two vulnerabilities in their Control V3 runtime system products.

Fujitsu Advisory - Fujitsu published an advisory that describes an improper credential storage vulnerability in their Software Infrastructure Manager product.

GE Advisory - GE published an advisory that discusses a FortiOS stack-based buffer overflow vulnerability.

HP Advisory - HP published an advisory that describes an elevation of privilege vulnerability in some HP and Samsung Printer software packages.

HPE Advisory - HPE published an advisory that discusses 48 vulnerabilities in their Fibre Channel and SAN Switches.

Omron Advisory #1 - Omron published an advisory that describes three vulnerabilities in their CX-Programmer product.

Omron Advisory #2 - Omron published an advisory that describes an improper validation of specified type of input vulnerability in their CJ Series CJ2 CPU units.

Omron Advisory #3 - Omron published an advisory that discusses the INFRA:HALT vulnerabilities in their Multi-function Compact Inverter 3G3MX2.

SEL Advisory - SEL published an advisory that announces that a new version of their Synchrowave Linux Platform is available to fix an undescribed vulnerability by closing Port 10250 on k3s.

Setelsa Advisory - Incibe-CERT published an advisory that describes an SQL injection vulnerability in the Setelsa ConacWin access control platform.

Splunk Advisory - Splunk published an advisory that describes a log injection vulnerability in their SOAR product.

Tanzu Advisories - Tanzu published 16 advisories, each with multiple vulnerabilities in various products.

WAGO Advisory #1 - VDE-CERT published an advisory that discusses an authentication bypass by capture replay vulnerability in the WAGO 758-918 ETHERNET Gateways.

WAGO Advisory #2 - VDE-CERT published an advisory that discusses 15 vulnerabilities in multiple WAGO products.

VMware Advisory - VMware published an advisory that describes two vulnerabilities in their Horizon Server.

 

For more details on these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-4fa - subscription required.

Thursday, July 13, 2023

Review – 7 Advisories and 2 Updates Published – 7-13-23

Today CISA’s NCCIC-ICS published six control system and 1 medical device security advisories for products from Honeywell, Rockwell Automation, Siemens (4), and BD. They also updated advisories for products from Enphase and Mitsubishi.

There were two additional Siemens advisories (and 12 updates that CISA no longer covers) that were published this week that were not addressed here (including the one for the missing CISA advisory). I will be addressing those this weekend.

Advisories

Honeywell Advisory - This advisory describes nine vulnerabilities in the Honeywell Experion PKS, LX, and PlantCruise DCS products.

Rockwell Advisory - This advisory describes a cross-site scripting vulnerability in the Rockwell PowerMonitor 1000 product.

SIMATIC Advisory #1 - This advisory discusses thirteen vulnerabilities in the Siemens SIMATIC MV500 series devices.

SIMATIC Advisory #2 - This advisory is currently returning a “Page Not Found” message.

SiPass Advisory - This advisory describes an improper input validation vulnerability in the Siemens SiPass Integrated access control product.

RUGGEDCOM ROX Advisory - This advisory discusses 21 vulnerabilities in the Siemens RUGGEDCOM ROX ethernet switches.

BD Advisory - This advisory describes eight vulnerabilities in a variety of BD products.

Updates

Enphase Update - This update provides additional information on an advisory that was originally published on June 22nd, 2023.

Mitsubishi Update - This update provides additional information on an advisory that was originally published on December 22nd, 2022.

 

For more details about these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-2-updates-published-916 - subscription required.

Saturday, June 3, 2023

Review – Public ICS Disclosure – Week of 5-27-23

This week we have 31 vendor disclosures from BD, Bosch, B&R, Contec, Eaton, Fuji Electric, Hitachi Energy (2), HPE (3), Mitsubishi, Splunk (15), VMware, and Zyxel (3). There are also four vendor updates from HPE (2) and Moxa (2). We also have 40 researcher reports for vulnerabilities for products from Delta Electronics (22), Fatek Automation (11), Mitsubishi, and Unified Automation (6). Finally, we have an exploit for products from Seagate.

Advisories

BD Advisory - BD published an advisory that discusses a buffer underflow vulnerability in some of their Kiestra products.

Bosch Advisory - Bosch published an advisory that describes a chip damaging vulnerability in their CPP13 and CPP14 cameras.

B&R Advisory - B&R published an advisory that discusses an abuse of service location protocol vulnerability in their ARPOL product.

Contec Advisory - Contec published an advisory that describes seven vulnerabilities in their CONPROSYS HMI System.

Eaton Advisory - Eaton published an advisory that describes a group access authorization logic vulnerability in their SecureConnect portal.

Fuji Electric - JP CERT published an advisory that describes three vulnerabilities in the Fuji Electric FRENIC RHC Loader.

Hitachi Energy Advisory #1 - Hitachi published an advisory that describes an improper output neutralization for logs vulnerability in their UNEM product.

Hitachi Energy Advisory #2 - Hitachi published an advisory that that describes an improper output neutralization for logs vulnerability in their FOXMAN-UN product.

HPE Advisory #1 - HPE published an advisory that describes an arbitrary code execution vulnerability in their Smart Storage Administrator (SSA) Offline product.

HPE Advisory #2 - HPE published an advisory that discusses four vulnerabilities in their HP-UX BIND product.

HPE Advisory #3 - HPE published an advisory that describes a denial of service vulnerability in their HP-UX IPv6 Stack.

Mitsubishi Advisory - Mitsubishi published an advisory that describes four vulnerabilities in their MELSEC iQ-R Series/iQ-F Series EtherNet/IP modules and EtherNet/IP configuration tools.

Splunk Advisories 1-3 - Splunk published three advisories for product updates for third party vulnerabilities.

Splunk Advisories 4-15 - Splunk published 12 advisories for individual vulnerabilities in multiple products.

VMware Advisory - VMware published an advisory that describes an insecure redirect vulnerability in their Workspace ONE Access and Identity Manager products.

Zyxel Advisory #1 - Zyxel published an advisory that describes two classic buffer overflow vulnerabilities in their firewalls.

Zyxel Adviosry #2 - Zyxel published an advisory that describes an OS command injection vulnerability in some of their NAS versions.

Zyxel Advisory #3 - Zyxel published an advisory that discusses recent attacks on their ZyWALL devices.

Updates

HPE Update #1 - HPE published an update for their StoreEasy Servers advisory that was originally published on February 14th, 2023 and most recently updated on March 23rd, 2023.

HPE Update #2 - HPE published an update for their OneView advisory that was originally published on February 6th, 2023.

Moxa Update #1 - Moxa published an update for their MXsecurity advisory that was originally published on March 8th, 2023 and most recently updated on May 23rd, 2023.

Moxa Update #2 - Moxa published an update for their Arm-based Computer advisory that was originally published on November 22nd, 2022.

Researcher Reports

Delta Electronics Reports - ZDI published 22 reports about individual vulnerabilities in the Delta CNCSoft-B product.

Fatek Reports - ZDI published eleven reports about individual vulnerabilities in the Fatek FvDesigner.

Mitsubishi Report - Talos Intelligence published a report describing a memory corruption vulnerability in the Mitsubishi MELSEC iQ-F FX5U MELSOFT.

Unified Automation Report #1 - Claroty published a report that describes an object validation vulnerability in the Unified Automation UaGateway.

Unified Automation Reports #2-6 - ZDI published five reports describing vulnerabilities in the Unified Automation UaGateway.

Exploits

Seagate Exploit - Ege Balci published an metsploit module for an OS command injection vulnerability in the Seagate Central External NAS Storage device.


For more details about these disclosures, including links to researcher reports and exploits, as well as a brief description of new information in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-5-27 - subscription required.


Saturday, May 20, 2023

Review – Public ICS Disclosures – Week of 5-13-23

This week we have 19 vendor disclosures from ABB, Broadcom (6), Flexera, Helmholz, HPE (3), MB Connect, OPC Foundation, SICK, TandD, Western Digital, WAGO, and Zyxel. There are also two updates from BD and HPE. Finally, we have two exploits for products from Ivanti and Siemens.

Advisories

ABB Advisory - ABB published an advisory that describes two vulnerabilities in their Terra AC wallbox.

Broadcom Advisory #1 - Broadcom published an advisory that discusses an out-of-bounds read vulnerability in their Brocade Directors, Brocade Fabric OS, and Brocade Switches.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an SQL injection vulnerability in their Brocade Fabric OS, Brocade SANnav, and Brocade Support Link.

Broadcom Advisory #3 - Broadcom published an advisory that discusses an incorrect permission assignment for critical resource vulnerability in their Brocade SANnav.

Broadcom Advisory #4 - Broadcom published an advisory that discusses an SQL injection vulnerability in their Brocade Fabric OS, Brocade SANnav, and Brocade Support Link.

Broadcom Advisory #5 - Broadcom published an advisory that discusses an SQL injection vulnerability in their Brocade Fabric OS, Brocade SANnav, and Brocade Support Link.

Broadcom Advisory #6 - Broadcom published an advisory that discusses an abuse of service location protocol vulnerability in their Brocade Fabric OS, Brocade SANnav, Brocade Support Link.

Flexera Advisory - Flexera published an advisory that discusses four vulnerabilities in their FlexNet Publisher.

Helmholz Advisory - CERT-VDE published an advisory that discusses two unnamed vulnerabilities in their myREX24 and myREX24.virtual products.

HPE Advisory #1 - HPE published an advisory that discusses four vulnerabilities in their HP-UX products.

HPE Advisory #2 - HPE published an advisory that discusses two vulnerabilities in their Edgeline servers.

HPE Advisory #3 - HPE published an advisory that discusses 11 vulnerabilities in their Cray EX235a Accelerator Blade.

MB Connect Advisory – MB Connect published an advisory that describes an incorrectly implemented object cache vulnerability in their mbCONNECT24 and mymbCONNECT24 products.

OPC Foundation - The OPC Foundation published an advisory that describes an uncontrolled resource consumption vulnerability in their OPC UA Legacy Java Stack.

SICK Advisory - The SICK product security page lists a new advisory for “Vulnerabilities in SICK FTMg”.

TandD Advisory - TandD published an advisory that describes four vulnerabilities in four end-of-life TandD products.

Western Digital Advisory - Western Digital published an advisory that describes four vulnerabilities in their My Cloud OS 5 Firmware.

WAGO Advisory - CERT-VDE published an advisory that describes an OS command injection vulnerability in multiple products from WAGO.

Zyxel Advisory #1 - Zyxel published an advisory that describes four vulnerabilities in their NBG-418N v2 router.

Zyxel Advisory #2 - Zyxel published an advisory that describes a command injection vulnerability in their NBG6604 router.

Updates

BD Update - BD published an update for their BD Totalys™ MultiProcessor that was originally published on October 4th, 2022.

HPE Update - HPE published an update for their PE Servers using certain Intel Chipset Firmware advisory that was originally published on February 8th, 2022 an most recently updated on March 3rd, 2022.

Exploits

Ivanti Exploit - Shelby Pace, Piotr Bazydlo published a Metasploit module for an unrestricted upload of file with dangerous type vulnerability in the Ivanti Avalanche.

Siemens Exploit - RoseSecurity published an exploit for a cross-site request forgery vulnerability in the SIMATIC S7-1200 CPU.

 

For more details on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-978 - subscription required.


Saturday, April 29, 2023

Review – Public ICS Disclosures – Week of 4-22-23

This week we have eighteen vendor disclosures from BD, Belden (2), Bosch (2), GE Gas Power (2), Genetec, Hitachi Energy (4), HPE, Mitsubishi, Moxa, Omron, Schneider, and VMware. There are two vendor updates from HPE, and Mitsubishi. Finally, we have an FDA report on the Illumina vulnerabilities.

Advisories

BD Advisory - BD published an advisory that describes a credential sharing incident that could affect their BD Kiestra product.

Belden Advisory #1 - Belden published an advisory that discusses an integer overflow or wraparound vulnerability in their HiSecOS and Cellular Router products.

Belden Advisory #2 - Belden published an advisory that discusses two vulnerabilities in their Hirschmann product line.

Bosch Advisory #1 - Bosch published an advisory that describes an incorrect authorization vulnerability in their B420 Ethernet communication module.

Bosch Advisory #2 - Bosch published an advisory that discusses a use of obsolete function vulnerability in their SLC-0-GPNT00300 interface module.

GE Gas Power Advisory #1 - GE published an advisory that discusses a path traversal vulnerability in multiple products.

GE Gas Power Advisory #2 - GE published an advisory that discusses a buffer underflow vulnerability in multiple products.

Genetec Advisory - Genetec published an advisory that discusses three vulnerabilities in the Security Center product.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses eight vulnerabilities in their Modular Switchgear Monitoring product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses four vulnerabilities in their RTU500 series product.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that discusses two vulnerabilities in their RTU500 series product.

Hitachi Energy Advisory #4 - Hitachi Energy published an advisory that discusses two vulnerabilities in their AFS65x, AFS67x, AFR67x and AFF66x series Products.

HPE Advisory - HPE published an advisory that describes an arbitrary code execution vulnerability in their ProLiant RL300 Gen11 Server.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses nine vulnerabilities in their FA product line.

Moxa Advisory - Moxa published an advisory that discusses two Trusted Computing Group TPM2.0 implementation vulnerabilities.

Omron Advisory - Omron published an advisory that describes a heap-based buffer overflow vulnerability in their CX-drive support tool.

Schneider Advisory - Schneider published an advisory that discusses a recently published exploit for vulnerabilities in their KNX building automation systems.

VMware Advisory - VMware published an advisory that describes four vulnerabilities in their Workstation and Fusion products.

Updates

HPE Update - HPE published an update for their IceWall advisory that was originally published on March 9th, 2018 and most recently updated on January 27th, 2023.

Mitsubishi Update - Mitsubishi published an update for their Ethernet port of MELSEC and MELIPC Series advisory that was originally published on November 30th, 2021 and most recently updated on November 24th, 2022.

Reports

Illumina Report - The Federal Drug Administration (FDA) published a letter to healthcare providers on the Illumina vulnerabilities reported this week by CISA.

 

For more details on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-b33 - subscription required.

Thursday, February 23, 2023

Review - 1 Advisory and 2 Updates Published – 2-23-23

Today, CISA’s NCCIC-ICS published a control system security advisory for products from PTC. They also updated advisories for products from Moxa and BD.

Advisories

PTC Advisory - This advisory describes two vulnerabilities in the PTC ThingWorx Edge.

NOTE: NCCIC-ICS reports that products from Rockwell Automation and GE Digital are affected by these products.

Updates

Moxa Update - This update provides additional information on an advisory that was originally published on November 29th, 2022.

BD Update - This update provides additional information on an advisory that was originally published on February 16th, 2023.

 

For more on these advisories and updates, including list of other vendors affected and a summary of changes in the updates – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/1-advisory-and-2-updates-published-c38 - subscription required.

Thursday, February 16, 2023

Review – 14 Advisories and 1 Update Published – 2-16-23

Today, CISA’s NCCIC-ICS published twelve control system security advisories for products from Sub-IoT and Siemens (12). They also published a medical device security advisory for products from BD. Finally, they updated an advisory for products from Delta Electronics.

NOTE 1: Siemens published one additional advisory on Tuesday that was not covered today by NCCIC-ICS. I will cover it this weekend.

NOTE 2: NCCIC-ICS continues to report on Siemens advisories that it will not report updated information on those advisories, so the seven updates published by Siemens this week will not be addressed by NCCIC-ICS.

Control System Advisories

Sub-IoT Advisory - This advisory describes an out-of-bounds write vulnerability in the Sub-IoT DASH 7 Alliance protocol implementation.

JY Open Advisory - This advisory describes three vulnerabilities in the Siemens JT Open Toolkit, JT Utilities, and Parasolid products.

Mendix Advisory - This advisory describes an improper access control vulnerability in the Siemens Mendix Applications.

COMOS Advisory - This advisory describes a classic buffer overflow vulnerability in the Siemens COMOS products.

SIMATIC Advisory - This advisory describes a TOCTOU race condition vulnerability in the Siemens SIMATIC industrial products.

RUGGEDCOM Advisory - This advisory describes seven TOCTOU race condition vulnerabilities in the Siemens RUGGEDCOM APE1808 product family.

TIA Project-Server Advisory - This advisory describes an untrusted search path vulnerability in the Siemens TIA Project-Server.

Simcenter Advisory - This advisory describes two vulnerabilities in the Siemens Simcenter Femap.

SiPass Advisory - This advisory describes an improper input validation vulnerability in the Siemens SiPass integrated AC5100, AC5102, AC5200, ACC-AP, Granta-MK3.

Brownfield Connectivity Advisory #1 - This advisory discusses eight vulnerabilities in the Siemens Brownfield Connectivity—Gateway products.

Brownfield Connectivity Advisory #2 - This advisory discusses four vulnerabilities in the Siemens Brownfield Connectivity Client.

SCALANCE Advisory - This advisory discusses an improper input validation vulnerability in the Siemens SCALANCE X200 IRT Products.

Medical Device Advisory

Solid Edge Advisory - This advisory describes 37 vulnerabilities in the Siemens Solid Edge products.

BD Advisory - This advisory this advisory describes a credentials management errors vulnerability in the BD Alaris Infusion Central.

Update

Delta Update - This update provides additional information on an advisory that was originally published on October 25th, 2022 and most recently updated on November 10th, 2022.

 

For more details about advisories, including links to researcher reports and 3rd-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/14-advisories-and-1-update-published - subscription required.

Saturday, January 14, 2023

Review: Public ICS Disclosures – Week of 1-7-23 – Part 1

This is a moderately busy Saturday after Cyber Tuesday. For Part 1 this week we have seventeen vendor disclosures from GE Grid Solutions (8), HP, HPE, Moxa, Omron (2), WAGO, Westermo, and Western Digital (2). We also have two vendor updates from BD and HPE. I will look at the Schneider and Siemens advisories and updates in Part 2.

Vendor Advisories

GE Grid Advisories - GE Grid Solutions published eight advisories this week. The advisories are only available to registered users.

HP Advisory - HP published an advisory that discusses three vulnerabilities in the AMD Client UEFI Firmware used in a variety of HP products.

HPE Advisory - HPE published an advisory that discusses a privilege escalation vulnerability in their SimpliVity 380 Gen9 Servers.

Moxa Advisory - Moxa published an advisory that discusses a hard-coded credential vulnerability (with known exploit) in their TN-4900 Series routers.

Omron Advisory #1 - JPCERT published an advisory that describes an active debug code vulnerability in the OMRON CP1L-EL20DR-D PLC.

Omron Advisory #2 - JPCERT published an advisory that describes an uninitiated pointer vulnerability in the OMRON CX-Motion-MCH application.

WAGO Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in multiple products from WAGO.

Westermo Advisory - Westermo published an advisory that discusses an unnamed vulnerability in their Ibex software where SNMP v3 is enabled.

Western Digital Advisory #1 - Western Digital published an advisory that describes a Host Boot ROM code vulnerability. This is a vulnerability in the UFS Host implementation.

NOTE: So, this is not a Western Digital vulnerability, but one that they discovered in an industry standard service. This could get ugly.

Western Digital Advisory #2 - Western Digital published an advisory that describes four vulnerabilities in their My Cloud OS 5 devices.

Vendor Updates

BD Update - BD published an update to their Totalys™ MultiProcessor advisory that was originally published on October 4th, 2022.

NOTE: NCCIC-ICS has not yet updated their advisory (ICSMA-22-277-01) for this information.

HPE Update - HPE published an update for their Nonstop advisory that was originally published on July 18th, 2022.

 

For more details on these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-b04 - subscription required.

Saturday, December 31, 2022

Review – Public ICS Disclosures – Week of 12-24-22

This week we have seven vendor disclosures from ABB, BD, Broadcom, Fuji Electric (2), Hitachi, and QNAP. Finally, we have a vendor update from Mitsubishi Electric.

Vendor Advisories

ABB Advisory - ABB published an advisory that describes two vulnerabilities in their NE843 Pulsar Plus Controller.

BD Advisory - BD published an advisory discussing an improper authentication vulnerability (with known exploit) in their Alaris products.

Broadcom Advisory - Broadcom published an advisory that discusses five Linux Kernel (ksmb module) vulnerabilities.

Fuji Advisory #1 - JP CERT published an advisory that describes three vulnerabilities in the Fuji V-Server.

Fuji Advisory #2 - JP CERT published an advisory that describes two vulnerabilities in the Fuji Electric V-SFT and TELLUS products.

Hitachi Advisory - Hitachi published an advisory that discusses 27 vulnerabilities in their Disk Array Systems.

QNAP Advisory - QNAP published an advisory that discusses that discusses one of the five recent Linux Kernel (ksmb module) vulnerabilities.

Vendor Updates

Mitsubishi Update - Mitsubishi published an update for their GENESIS64 advisory that was originally published on December 13th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-347-01) for this information.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-388 - subscription required.

 
/* Use this with templates/template-twocol.html */