Showing posts with label Baicells. Show all posts
Showing posts with label Baicells. Show all posts

Saturday, March 4, 2023

Review - Public ICS Disclosure – Week of 3-3-23

This week we have 25 vendor disclosures from ABB (2), Aruba Networks, BaiCells, Bosch, B&R (2), Hitachi Energy, HPE (7), JTEKT Electronics, Milestone, Reillo, StrongSwan, Tanzu (2), VMware, WAGO, Western Digital, and Wireshark. We also have three vendor updates from HPE (2) and Mitsubishi. Finally we have ten researcher reports for products from Osprey (9) and DJI drones.

Vendor Advisories

ABB Advisory #1 - ABB published an advisory that discusses an improper resource shutdown or release vulnerability in ABB AC 800PEC and AC 800PEC-based products.

ABB Advisory #2 - ABB published an advisory that describes an improper authentication vulnerability in their S+ Operations products.

Aruba Advisory - Aruba published an advisory that describes 33 vulnerabilities in their ArubaOS product.

BaiCells Advisory - BaiCells published an advisory that describes a command injection vulnerability in their EG7035-M11 CPE Series products.

Bosch Advisory - Bosch published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their FL MGUARD and TC MGUARD routers.

B&R Advisory #1 - B&R published an advisory that describes five vulnerabilities in their APROL database.

B&R Advisory #2 - B&R published an advisory that discusses five vulnerabilities in their Mobile Panel and Power Panel products.

Hitachi Energy Advisory - Hitachi published an advisory that describes an update signature validation vulnerability in their Relion® 670, 650 and SAM600-IO Series Products.

HPE Advisory #1 - HPE published an advisory that discusses four improper access control vulnerabilities in their Moonshot/Edgeline Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that discusses a privilege escalation vulnerability in their Apollo, XL Servers.

HPE Advisory #4 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #5 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #6 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #7 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #8 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML/Microserver Servers.

JTEKT Advisory - JP Cert published an advisory that describes three vulnerabilities in the JTEKT Kostac PLC Programming Software.

Milestone Advisory - Milestone published an advisory that announces that their online services no longer support TLS v1.0 and TLS v1.1 protocols.

Riello Advisory - Incibe CERT published an advisory that describes three vulnerabilities in the Riello UPS NetMan 204.

StrongSwan Advisory - StrongSwan published an advisory that describes a certificate verification vulnerability in StrongSwan.

Tanzu Advisory #1 - Tanzu published an advisory that discusses three vulnerabilities in multiple Tanzu products.

Tanzu Advisory #2 - Tanzu published an advisory that discusses two vulnerabilities in multiple Tanzu products.

VMware Advisory - VMware published an advisory that describes a passcode bypass vulnerability in their Workspace ONE Content product.

WAGO Advisory - CERT VDE published an advisory that describes four vulnerabilities in multiple WAGO products.

Western Digital Advisory - Western Digital published an advisory that the latest version of their SanDisk PrivateAccess no longer supports “insecure TLS 1.0 and TLS 1.1 protocols”.

Wireshark Advisory - Wireshark published an advisory that describes a packet injection vulnerability in their ISO 15765 and ISO 10681 dissectors.

Vendor Updates

HPE Update #1 - HPE published an update for their Intel 500 Series Ethernet Controllers advisory that was originally published on February 14th, 2023.

HPE Update #2 - HPE published an update for their ProLiant DL/ML/Microserver Servers that was originally published on February 14th, 2023.

Mitsubishi Update - Mitsubishi published an update for their WEB Server Function on MELSEC Series that was originally published on January 17th, 2023 and most recently updated on January 26th, 2023.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-23-017-02) for this new information.

Researcher Reports

Osprey Report #1 - Zero Science published a report that describes a security bypass vulnerability in the Osprey Pump Controller.

Osprey Report #2 - Zero Science published a report that describes an information disclosure vulnerability in the Osprey Pump Controller.

Osprey Report #3 - Zero Science published a report that describes an administrator backdoor vulnerability in the Osprey Pump Controller.

Osprey Report #4 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #5 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #6 - Zero Science published a report that describes a reflected cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #7 - Zero Science published a report that describes an authentication bypass vulnerability in the Osprey Pump Controller.

Osprey Report #8 - Zero Science published a report that describes a cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #9 - Zero Science published a report that describes a remote code execution vulnerability in the Osprey Pump Controller.

DJI Drones Report - Nico Schiller, et. al. from the Ruhr University Bochum published a report that describes multiple security vulnerabilities in the control system for DJI consumer drones.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-3-3 - subscription require.

Thursday, March 2, 2023

Review – 4 Advisories and 1 Update – 3-2-23

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Rittal, Baicells, and Mitsubishi. They also published a medical device security advisory for products from Medtronic. They updated a control system security advisory for products from Mitsubishi.

Advisories

Rittal Advisory - This advisory describes an improper access control vulnerability in the Rittal CMC III locks.

Baicells Advisory - This advisory described a command injection vulnerability in the Baicells LTE TDD eNodeB devices.

Mitsubishi Advisory - This advisory describes a plain-text storage of a password vulnerability in the Mitsubishi Electric MELSEC iQ-F products.

Medtronic Advisory - This advisory describes an unverified password change vulnerability in the Medtronic Micros Clinician (A51200) app and InterStim X Clinician (A51300).

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on July 30th, 2020 and most recently updated on November 22nd, 2022.

 

For more details on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/4-advisories-and-1-update-3-2-23 - subscription required.

Saturday, February 11, 2023

Review – Public ICS Disclosures – Week of 2-4-23

This week we have eleven vendor disclosures from ABB, Baicells, Dahua, Palo Alto Networks (5), Ruckus, and Zyxel Networks (2). We also have three vendor updates from CONTEC, HPE, and Moxa. Finally, we have thirteen researcher reports on products from Siemens, and Open Design Alliance (12).

NOTE: There have been problems with the NIST NVD CVE listings this morning. They have been slow to load or have not been found. Hopefully this will be corrected in the near future.

Vendor Disclosures

Baicells Advisory - Baicells published an advisory that describes a cross-site scripting vulnerability in their Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices.

Dahua Advisory - Dahua published an advisory that describes an unauthorized modification of device timestamp vulnerability in some of their embedded products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that discusses an improper privilege management vulnerability in SUDO.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses the OpenSSL vulnerabilities disclosed Feb 7, 2023.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes a protection mechanism failure vulnerability in their Cortex XDR agent.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an information disclosure vulnerability in their Cortex XDR agent.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes a file disclosure vulnerability in their Cortex XSOAR server.

Ruckus Advisory - Ruckus published an advisory that describes a cross-site request forgery vulnerability in multiple products using their AP Web application.

NOTE: Multiple end-of-life products are listed as being affected by this vulnerability.

Zyxel Advisory #1 - Zyxel published an advisory that describes a command injection vulnerability in their firewalls.

Zyxel Advisory #2 - Zyxel published an advisory that describes an improper check for unusual or exceptional conditions vulnerability in their Aps.

Vendor Updates

CONTEC Update - JP CERT published an update for their Solar View Compact advisory that was originally published on May 26th, 2022 and most recently updated on December 13th, 2022.

HPE Update - HPE published an update for their OneView advisory that was originally published on January 31st, 2023.

Moxa Update - Moxa published an update for their UC Series advisory that was originally published on November 29th, 2023.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-333-04) for this new information.

Researcher Reports

Siemens Report - Otorio published a report describing two vulnerabilities in the Siemens Automation License Manager.

ODA Report #1 - The Zero Day Initiative published a report that describes a memory corruption vulnerability in the ODA Drawing SDK.

ODA Report #2 - ZDI published a report that describes a memory corruption vulnerability in the ODA Drawing SDK.

ODA Report #3 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report # 4 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #5 - ZDI published a report that describes a heap-based buffer overflow vulnerability in the ODA Drawing SDK.

ODA Report #6 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #7 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #8 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report # 9 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #10 - ZDI published a report that describes an out-of-bounds write vulnerability in the ODA Drawing SDK.

ODA Report #11 - ZDI published a report that describes a heap-based buffer overflow vulnerability in the ODA Drawing SDK.

ODA Report #12 - ZDI published a report that describes a use-after-free vulnerability in the ODA Drawing SDK.

 

For more details about these disclosures, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-6e9 - subscription required.

Saturday, February 4, 2023

Review – Public ICS Disclosures – Week of 1-28-23

This week we have twelve vendor disclosures from BaiCells, B&R, Hitachi, HP, HPE, JTEKT Electronics, Moxa, Pulse Secure (2), QNAP, and VMware (2). There is also a vendor update from VMware. Finally, we have two researcher reports for products from Sierra Wireless and describing vulnerabilities in the Open Charge Point Protocol for electric vehicle charging stations.

Advisories

BaiCells Advisory - BaiCells published an advisory that describes a use of hard-coded credentials vulnerability in their Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices.

B&R Advisory - B&R published an advisory that describes five vulnerabilities in their ARPOL database.

Hitachi Advisory - Hitachi published an advisory that discusses 60 vulnerabilities in their Disk Array Systems.

HP Advisory - HP published an advisory that describes an escalation of privilege vulnerabilities in their Factory Preinstalled Images.

HPE Advisory - HPE published an advisory that discusses a use-after-free vulnerability in their HPE OneView.

JTEKT Advisory - JP CERT published an advisory that describes seven vulnerabilities in the JTEKT Screen Creator Advance product.

Moxa Advisory - Moxa published an advisory that describes six vulnerabilities in their SDS-3008 Series web server.

Pulse Secure Advisory #1 - Pulse Secure published an advisory that discusses four OpenSSL vulnerabilities.

Pulse Secure Advisory #2 - Pulse Secure published an advisory that describes a cross-site request forgery vulnerability in their Pulse Connect Secure.

QNAP Advisory - QNAP published an advisory that describes an SQL injection vulnerability in their QTS or QuTS hero products.

VMware Advisory #1 - VMware published an advisory that describes a cross-site request forgery bypass vulnerability in their vRealize Operations (vROps).

VMware Advisory #2 - VMware published an advisory that describes an arbitrary file deletion vulnerability in their VMware Workstation product. 

Updates

VMware Update - VMware published an update for their vRealize Log Insight advisory that was originally published on January 24th, 2023.

Researcher Reports

Sierra Wireless Report - Otorio published a report describing two vulnerabilities in the Sierra Wireless AirLink products. The report contains proof-of-concept code.

OCPP Report - SaiFlow published a report describing two vulnerabilities in the WebSocket communications used by the Open Charge Point Protocol (OCPP).

 

For more details about these disclosures, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-768 - subscription required.

Thursday, February 2, 2023

Review – 5 Advisories and 1 Update Published – 2-2-23

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Delta Electronics (3), Baicells Technologies, and Mitsubishi Electric. They also updated an advisory for Mitsubishi.

Advisories

Delta Advisory #1 - This advisory describes two vulnerabilities with known exploits in the Delta DX-2100-L1-CN industrial ethernet router.

NOTE: I briefly discussed the vulnerabilities on December 10th, 2022.

Delta Advisory #2 - This advisory describes an OS command injection vulnerability with known exploit in the Delta DVW-W02W2-E2 industrial ethernet router.

NOTE: I briefly discussed the vulnerabilities on December 10th, 2022.

Delta Advisory #3 - This advisory describes three vulnerabilities in the Delta DIAScreen software configuration tool for Delta devices.

Baicells Advisory - This advisory describes a command injection vulnerability in the Baicells Nova LTE TDD eNodeB devices.

NOTE: Baicells recently reported another vulnerability that has not been reported by NCCIC-ICS. I will report on it this weekend.

Mitsubishi Advisory - This advisory describes two vulnerabilities in the Mitsubishi GOT Mobile Function on GOT2000 Series and GT SoftGOT2000.

Updates

Mitsubishi Update - This update provides additional information on an advisory that was originally published on August 9th, 2022 and most recently updated on November 1st, 2022.

 

For more information on these advisories, including links to researcher reports, see my article on CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-1-update-published-0b1 - subscription required.

 
/* Use this with templates/template-twocol.html */