Showing posts with label Blackberry. Show all posts
Showing posts with label Blackberry. Show all posts

Saturday, October 5, 2024

Review – Public ICS Disclosures – Week of 9-28-24

This week we have 13 vendor disclosures from Bosch (2), Cisco, DrayTek (2), Hitachi, HP, JTEKT, QNAP, SEL (2), Splunk, Westermo, and WithSecure. We have two vendor updates from Dell. Finally, we have two exploits for products from ABB and Blackberry.

Advisories

Bosch Advisory #1 - Bosch published an advisory that describes a sensitive information disclosure vulnerability in their Configuration Manager.

Bosch Advisory #2 - Bosch published an advisory that discusses three vulnerabilities in their PRC7000 product.

Cisco Advisory - Cisco published an advisory that describes two vulnerabilities in their Small Business Dual WAN Gigabit VPN Routers.

DrayTek Advisory #1 - DrayTek published an advisory that describes 14 vulnerabilities (with exploits available) in multiple Vigor routers.

DrayTek Advisory #2 - DrayTek published an advisory that describes seven classic buffer overflow vulnerabilities in multiple Vigor routers.

Hitachi Advisory - Hitachi published an advisory that discusses an improper input validation vulnerability in their Cosminexus Component Container.

HP Advisory - HP published an advisory that describes an escalation of privilege vulnerability in their business notebook PCs.

QNAP Advisory - QNAP published an advisory that discusses the CUPS vulnerabilities.

SEL Advisory #1 - SEL published a new version notice for their SEL-5030 acSELerator QuickSet Software that includes a description of a cybersecurity enhancement.

SEL Advisory #2 - SEL published a new version notice for their SEL-5813 Backup and Recovery Tool (BaRT) that includes a description of a cybersecurity enhancement.

Splunk Advisory - Splunk published an advisory that discusses four vulnerabilities in their Add-on for Amazon Web Services.

Westermo Advisory - Westermo published an advisory that describes a session hijacking vulnerability in their IbexOS Web Interface.

WithSecure Advisory - WithSecure published an advisory that describes a denial-of-service vulnerability in their Atlant Product.

Updates

Dell Update #1 - Dell published an update for their ThinOS advisory that was originally published on September 9th, 2024, and most recently updated on September 18th, 2024. The

Dell Update #2 - Dell published an update for their ThinOS advisory that was originally published on June 12th, 2024, and most recently updated on September 9th, 2024.

Exploits

ABB Exploit - LiquidWorm published an exploit for a file disclosure vulnerability in the ABB Cylon Aspect.

Blackberry Exploit - SEC Consult published an exploit for an uninstall password bypass vulnerability in the Blackberry CylanceOPTICS product.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-d4d - subscription required.

Saturday, September 28, 2024

Review – Public ICS Disclosures – Week of 9-21-24

This week we have 17 vendor disclosures from Broadcom (2), Cisco, GE Vernova, HPE (5), Palo Alto Networks, SEL, SICK, WatchGuard (3), Western Digital, and Zyxel. There are also 3 updates from CODESYS, ELECOM, and HPE. We also have 6 researcher reports for products from ABB (4), Blackberry, and Linear Solutions. Finally, we have 3 exploits for products from BlackNET, Positron, and Texas Instruments.

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses the Blast-Radius vulnerability.

Broadcom Advisory #2 - Broadcom published version release notice for their Brocade Fabric OS that lists the previously disclosed vulnerabilities that are corrected in the latest version.

Cisco Advisory - Cisco published an advisory that describes an improper access control vulnerability in their Industrial Ethernet 4000, 4010, and 5000 Series Switches.

GE Vernova Advisory - GE published an advisory that describes two vulnerabilities in their WorkstationST products.

HPE Advisory #1 - HPE published an advisory that discusses the regreSSHion vulnerability in their HPE Superdome Flex and Superdome Flex 280 servers.

HPE Advisory #2 - HPE published an advisory that describes three command injection vulnerabilities in their Aruba Access Points products.

HPE Advisory #3 - HPE published an advisory that describes a cross-site request forgery vulnerability in their IceWall Agent products.

HPE Advisory #4 - HPE published an advisory that discusses a protection mechanism failure vulnerability in their SimpliVity Servers.

HPE Advisory #5 - HPE published an advisory that discusses an inconsistent flow control management vulnerability in their SimpliVity Servers.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses the CUPS vulnerabilities.

SEL Advisory - SEL published a new version notice for their SEL-5033 acSELerator RTAC software that describes a cybersecurity enhancement.

SICK Advisory - SICK published an advisory that describes a missing authentication for critical function vulnerability in their MSC800 track and trace controller.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes an incorrect authorization vulnerability (with publicly available exploit) in their Authentication Gateway.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes an incorrect authorization vulnerability (with publicly available exploit) in their Authentication Gateway.

WatchGuard Advisory #3 - WatchGuard published an advisory that describes an improper handling of exceptional or unusual conditions vulnerability (with publicly available exploit) in their Single Sign-On Client.

Western Digital Advisory - Western Digital published an advisory that describes an improper restriction of operations within the bounds of a memory buffer vulnerability in their My Cloud firmware.

Zyxel Advisory - Zyxel published an advisory that describes four improper restriction of operations within the bounds of a memory buffer vulnerabilities in multiple Zyxel products.

Updates

CODESYS Update - CODESYS published an update for their Control V3 web server advisory that was originally published on August 29th, 2024.

ELECOM Update - JP-CERT published an update for their ELECOM wireless LAN advisory that was originally published on August 27th, 2024.

HPE Update - HPE published an update for their ProLiant DL/ML/XL, Edgeline, MicroServer and Synergy Servers advisory that was originally published on September 16th, 2024 and most recently updated on September 19th, 2024.

Researcher Reports

ABB Report #1 - Zero Science published a report that describes a files or directories accessible to external parties vulnerability (with an associated exploit) in the ABB ASPECT building management software.

ABB Report #2 - Zero Science published a report that describes an improper input validation vulnerability (with an associated exploit) in the ABB ASPECT building management software.

ABB Report #3 - Zero Science published a report that describes a command injection vulnerability (with an associated exploit) in the ABB ASPECT Control Engines.

ABB Report #4 - Zero Science published a report that describes a use of default credentials vulnerability (with an associated exploit) in the ABB ASPECT system.

Blackberry Report - SEC Consult published a report that describes an authentication bypass by alternate path or channel vulnerability in the Blackberry CylanceOPTICS Windows Installer Package.

Linear Solutions Report - SSD published a report that describes a remote code execution vulnerability in the Linear eMerge E3 access control product.

Exploits

BlackNET Exploit - bRpsd published an exploit for a missing authentication for critical operation vulnerability in the BlackNET secure transport layer.

Positron Exploit - Indoushka published an exploit for a cross-site request forgery in the Positron Broadcast Signal Processor TRA7005.

TI Exploit - crypt0d1v3r published a proof-of-concept toolkit for a denial of service vulnerability in the TI bluetooth stack.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-2c2 - subscription required.

Sunday, September 15, 2024

Review – Public ICS Disclosures – Week of 9-7-24 – Part 2

For Part 2 we have five additional vendor disclosures from Schneider (2), Siemens, and Zyxel (2). We also have 26 vendor updates from Cisco, CODESYS, HP, Schneider (3), and Siemens (20). Finally, we have an exploit for products from BlackBerry.

Advisories

Schneider Advisory #1 - Schneider published an advisory that describes an improper privilege management vulnerability in their Vijeo Designer products.

Schneider Advisory #2 - Schneider published an advisory that describes a cross-site scripting vulnerability in their EcoStruxure Power Monitoring Expert (PME) and EcoStruxure Power Operation (EPO) products.

Siemens Advisory - Siemens published an advisory that describes an uncontrolled resource consumption vulnerability in their SIMATIC S7-200 SMART devices.

Zyxel Advisory #1 - Zyxel published an advisory that describes an OS command injection vulnerability in their NAS products.

Zyxel Advisory #2 - Zyxel published an advisory that describes an insufficient entropy vulnerability in their GS1900 series switches.

Updates

Cisco Update - Cisco published an update for their regreSSHion advisory that was originally published on July 2nd, 2024, and most recently updated on September 5th, 2024.

CODESYS Update - CODESYS published an update for their OSCAT Basic library advisory that was originally published on August 29th, 2024.

HP Update - HP published an update for their Plantronics advisory that was originally published on December 20th, 2023, most recently updated on June 26th, 2024.

Moxa Update - Moxa published an update for their regreSSHion advisory that was originally published on August 2nd, 2024, and most recently updated on August 23rd, 2024.

Schneider Update #1 - Schneider published an update for their PowerLogic P5 advisory that was originally published on June 11th, 2024.

Schneider Update #2 - Schneider published an update for their EcoStruxure Power Monitoring Expert advisory that was originally published on March 14th, 2023, and most recently updated on July 11th, 2023.

Schneider Update #3 - Schneider published an update for their  BadAlloc advisory that was originally published on November 9th, 2021, and most recently updated on August 13th, 2024.

Siemens Update #1 - Siemens published an update for their User Management Component advisory that was originally published on December 12th, 2023, and most recently updated on August 13th, 2024.

Siemens Update #2 - Siemens published an update for their Industrial Products advisory that was originally published on May 14th, 2024, and most recently updated on July 9th, 2024.

Siemens Update #3 - Siemens published an update for their LOGO! 8 BM Devices advisory that was originally published on October 11th, 2022, and most recently updated on December 12th, 2023.

Siemens Update #4 - Siemens published an update for their LOGO! V8.3 BM Devices advisory that was originally published on August 13th, 2024.

Siemens Update #5 - Siemens published an update for their SIMATIC WinCC advisory that was originally published on July 9th, 2024.

Siemens Update #6 - Siemens published an update for their Electromagnetic Fault Injection advisory that was originally published on December 12th, 2023.

Siemens Update #7 - Siemens published an update for their Fortigate NGFW advisory that was originally published on March 12th, 2024, and most recently updated on July 9th, 2024.

Siemens Update #8 - Siemens published an update for their SENTRON 7KM PAC3120 advisory that was originally published on March 12th, 2024.

Siemens Update #9 - Siemens published an update for their LOGO! 8 BM advisory that was originally published on March 9th, 2021, and most recently updated on December 12th, 2023.

Siemens Update #10 - Siemens published an update for their SIMATIC WinCC advisory that was originally published on February 13th, 2024, and most recently updated on July 9th, 2024.

Siemens Update #11 - Siemens published an update for their Fortigate NGFW advisory that was originally published on July 9th, 2024, and most recently updated on August 13th, 2024.

Siemens Update #12 - Siemens published an update for their OPC Foundation advisory that was originally published on March 11th, 2024, and most recently updated on May 14th, 2024.

Siemens Update #13 - Siemens published an update for their SCALANCE W700 802.11 AX advisory that was originally published on June 11th, 2024.

Siemens Update #14 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 11th, 2023, and most recently updated on June 11th, 2024.

Siemens Update #15 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on April 9th, 2024, and most recently updated on July 9th, 2024.

Siemens Update #16 - Siemens published an update for their Industrial Real-Time devices advisory that was originally published on October 8th, 2019, and most recently updated on May 9th, 2023.

Siemens Update #17 - Siemens published an update for their PROFINET DCP Implementation advisory that was originally published on May 8th, 2017, and most recently updated on July 9th, 2024.

Siemens Update #18 - Siemens published an update for their SINUMERIK ONE advisory that was originally published on December 12th, 2023.

Siemens Update #19 - Siemens published an update for their Mendix Runtime advisory that was originally published on August 10th, 2024.

Siemens Update #20 - Siemens published an update for their OPC UA Server advisory that was originally published on July 9th, 2024.

Exploit

BlackBerry Exploit - Brendan Coles published a Metasploit module for a lack of authentication for sensitive operations vulnerability in the BlackBerry QNX system.

For more information on these disclosures, including a brief summary of the changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-d3d - subscription required.


Saturday, November 18, 2023

Review – Public ICS Disclosures – Week of 11-11-23 – Part 1

A busy Cyber Tuesday week. For Part 1 we have 26 vendor disclosures from Aruba Networks, Blackberry, FortiGuard (3), Hitachi Energy, HPE (10), ICSSolution, Luxion, Philips, SEL (2), and Splunk (6).

Advisories

Aruba Advisory - Aruba published an advisory that describes 14 vulnerabilities in their Access Points products.

Blackberry Advisory - Blackberry published an advisory that describes an improper input validation vulnerability in their QNX Networking Stack.

FortiGuard Advisory #1 - FortiGuard published an advisory that discusses two vulnerabilities in their FortiOS product.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper integrity check value vulnerability in their FortiOS and FortiProxy VM products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a NULL pointer dereference vulnerability in their FortiOS and FortiProxy products.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses a deserialization of untrusted data vulnerability that is on the CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

HPE Advisory #1 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their Apollo and XL servers.

HPE Advisory #2 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their ProLiant DX Servers.

HPE Advisory #3 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/XL servers and Cray Supercomputer.

HPE Advisory #4 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their StoreEasy Server.

HPE Advisory #5 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their ProLiant DL/ML and Microservers.

HPE Advisory #6 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/DX/XL Server. These are third-party (AMD) vulnerabilities

HPE Advisory #7 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their Synergy Servers.

HPE Advisory #8 - HPE published an advisory that discusses an improper access control vulnerability in their SimpliVity Servers.

HPE Advisory #9 - HPE published an advisory that discusses the  Downfall Attacks vulnerability in their SimpliVity Servers.

HPE Advisory #10 - HPE published an advisory that discusses an unauthorized error injection vulnerability in their SimpliVity Servers.

ICSSolution Advisory - INCIBE-CERT published an advisory that describes two vulnerabilities in the ICSSolution ICS Business Manager product.

Luxion Advisory - Luxion published an advisory that describes an improper input validation vulnerability in their KeyShot product.

Philips Advisory - Philips published an advisory that discusses the Citrix Bleed vulnerability that is listed in the CISA KEV catalog.

SEL Advisories - SEL published two advisories for unlisted cybersecurity concerns.

Splunk Advisory #1 - Splunk published an advisory that discusses an insufficient verification of data authenticity vulnerability in their Add-on for Amazon Web Services.

Splunk Advisory #2 - Splunk published an advisory that discusses multiple unnamed third-party vulnerabilities in their Add-on for Google Cloud Platform.

Splunk Advisory #3 - Splunk published an advisory that describes a cross-site scripting vulnerability in the Search Page in Splunk Enterprise.

Splunk Advisory #4 - Splunk published an advisory that describes five vulnerabilities in their Enterprise product.

Splunk Advisory #5 - Splunk published an advisory that discusses four vulnerabilities in their Enterprise Cloud product.

Splunk Advisory #6 - Splunk published an advisory that discusses four vulnerabilities in their Universal Forwarder product.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-713 - subscription required.

Saturday, January 15, 2022

Review - Public ICS Disclosure – Week of 1-8-22 – Part 1

This week, as we have come to expect for the Saturday after 2nd Tuesday, we have a full slate of ICS disclosures, including more Log4Shell disclosures, that will take multiple posts to deal with. In Part 1 we have fourteen vendor disclosures from Belden, Blackberry, Dynalite, Hitachi Energy, HPE, Moxa, Palo Alto Networks (4), QNAP (3), and Yokogawa. There is also an update from HPE. There were also two researcher reports for products from IDEMIA and ODA. Finally, we have an exploit for products from SonicWall.

Part 2 of this post will address the Schneider advisories and updates that were published on Tuesday as well as the Siemens updates that were not addressed by NCCIC-ICS this week.

Belden Advisory - Belden published an advisory describing six vulnerabilities in their Tofino and Eagle products.

BlackBerry Advisory - BlackBerry published an advisory describing an elevation of privilege vulnerability in their QNX Neutrino Kernel.

Dynalite Advisory - Dynalite published an advisory discussing two vulnerabilities in their DDNG-BACnet gateway and in Niagara SOFTJACE products.

Hitachi Energy Advisory - Hitachi Energy published an advisory discussing four vulnerabilities in their e-mesh™ Energy Management System (EMS) Product.

HPE Advisory HPE published an advisory describing a remote access vulnerability in their Ezmeral Data Fabric.

Moxa Advisory - Moxa published an advisory describing four vulnerabilities in their VPort 06EC-2V Series and VPort 461A Series IP Cameras and Video Servers.

Palo Alto Advisory #1 - Palo Alto published an advisory describes an uncontrolled search path element vulnerability in their Cortex XDR Agent.

Palo Alto Advisory #2 - Palo Alto published an advisory describes an untrusted search path element vulnerability in their Cortex XDR Agent.

Palo Alto Advisory #3 - Palo Alto published an advisory describing a link following vulnerability in their Cortex XDR Agent.

Palo Alto Advisory #4 - Palo Alto published an advisory describing a file and directory information exposure vulnerability in their Cortex XDR Agent.

Phoenix Contact Advisory - Phoenix Contact published an advisory discussing the NUCLEUS:13 vulnerabilities in their BLUEMARK X1 / LED / CLED printers.

QNAP Advisory #1 - QNAP published an advisory describing a remote code execution vulnerability in their QTS and QuTS hero products.

QNAP Advisory #2 - QNAP published an advisory describing five separate classic buffer overflow vulnerabilities in their QVR Elite, QVR Pro, and QVR Guard products.

QNAP Advisory #3 - QNAP published an advisor describing two vulnerabilities in their QcalAgent.

Yokogawa Advisor - Yokogawa published an advisory discussing a link following vulnerability in the license function in Yokogawa products.

HPE Update - HPE published an update for their Integrated Lights-out 4 advisory that was originally published  on August 23rd, 2017.

IDEMIA Report - Positive Technologies published a report of a TLS bypass vulnerability in biometric identification vulnerabilities in products from IDEMIA.

ODA Report - ZDI published a report describing a JPG File Parsing Memory Corruption in the Open Design Alliance (ODA) Drawings Explorer.

SonicWall Exploit - jbaines-r7 published Metasploit module for a command injection vulnerability in the SonicWall SMA 100 Series.

For more details on the above disclosures, including links to 3rd party advisories and vulnerability exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-1-8 - subscription required.

Saturday, November 20, 2021

Review - Public ICS Disclosures – Week of 11-13-21 – Part 1

Review - Public ICS Disclosures – Week of 11-13-21 – Part 1

This has been a very busy week for vendor disclosures, so I will be doing this as a two-part report again this week. This week we have 17 vendor disclosures from Blackberry, Braun (2), WAGO (3), Dell, Gallagher (6), and ABB (4).

Blackberry Advisory - Blackberry published an advisory describing a remote code execution vulnerability in their QNX Software Development Platform.

Braun Advisory #1 - Braun published an advisory discussing the NUCLEUS:13 vulnerabilities.

Braun Advisory #2 - Braun published an advisory discussing the INFRA:HALT vulnerabilities.

WAGO Advisory #1 - CERT-VDE published an advisory discussing six vulnerabilities in a number of WAGO PLCs.

WAGO Advisory #2 - CERT-VDE published an advisory discussing an improper handling of exceptional conditions vulnerability in a number of WAGO PLC’s.

WAGO Advisory #3 - CERT-VDE published an advisory discussing the NUCLEUS:13 vulnerabilities.

Dell Advisory - Dell published an advisory describing five vulnerabilities in their Wyse Management Suite.

Gallagher Advisory #1 - Gallagher published an advisory describing an unquoted service path vulnerability in their Controller Service.

Gallagher Advisory #2 - Gallagher published an advisory describing an improper privilege validation vulnerability in their Command Centre Server.

Gallagher Advisory #3 - Gallagher published an advisory describing an improper certificate validation vulnerability in their Command Centre Server.

Gallagher Advisory #4 - Gallagher published an advisory describing an improper validation of the cloud-certificate chain in their Mobile Connect for Android.

Gallagher Advisory #5 - Gallagher published an advisory describing an improper validation of the cloud-certificate chain in their Command Centre Mobile Client for Android.

Gallagher Advisory #6 - Gallagher published an advisory describing an incomplete comparison with missing factors vulnerability in their Gallagher Controller.

ABB Advisory #1 - ABB published an advisory discussing two vulnerabilities in their Hitachi Energy RTU500 series.

ABB Advisory #2 - ABB published an advisory discussing the BadAlloc vulnerabilities in their Hitachi Energy RTU500 series.

ABB Advisory #3 - ABB published an advisory discussing three vulnerabilities in their Hitachi Energy RTU500 Series.

ABB Advisory #4 - ABB published an advisory describing a validation error vulnerability in their Hitachi Energy RTU500 Series.

For more information on these advisories, including links to third-party advisories and exploits, see  my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-880 - subscription required.

Saturday, November 13, 2021

Review - Public ICS Disclosures – Week of 11-6-21 – Part 1

This week we have twelve vendor disclosures from Blackberry, Draeger, Open Design Alliance, HPE (4), Milestone, Phoenix Contact, QNAP, and VMware (2). There is also an update from CODESYS. Finally, we have a research report from Forescout on the plethora of TCP/IP vulnerability disclosures.

I will cover the remaining Siemens and Schneider advisories and updates that were published Tuesday, but not yet covered by NCCIC-ICS in Part 2.

Blackberry Advisory - Blackberry published an advisory describing three vulnerabilities in their Protect for Windows product.

Draeger Advisory - Draeger published an advisory discussing the NUCLEUS:13 vulnerabilities.

ODA Advisory - Incibe Cert published an advisory describing nine vulnerabilities in the ODAViewer.

HPE Advisory #1 - HPE published an advisory describing an arbitrary code execution vulnerability in their ProLiant Gen10 Plus Servers.

HPE Advisory #2 - HPE published an advisory describing 15 vulnerabilities in their ProLiant and Apollo Gen10 and Gen10 Plus servers.

HPE Advisory #3 - HPE published an advisory discussing  three vulnerabilities in their ProLiant, Apollo, Synergy Gen10 and Gen10 Plus Servers.

HPE Advisory #4 - HPE published an advisory discussing an escalation of privilege vulnerability in their ProLiant, Apollo, Edgeline, and Synergy Servers.

Milestone Advisory - Milestone published an advisory describing an arbitrary file access vulnerability in their XProtect DLNA server.

Phoenix Contact Advisory - Phoenix Contact published an advisory describing two vulnerabilities in their FL MGUARD 1102/1105 products.

QNAP Advisory - QNAP published an advisory describing a cross-site scripting vulnerability in their NAS running QmailAgent.

VMware Advisory #1 - VMware published an advisory describing a privilege escalation vulnerability in their vCenter Server.

VMware Advisory #2 - VMware published an advisory discussing a denial-of-service vulnerability in their Tanzu Application Service for VMs.

CODESYS Update - CODESYS published an update for their V2 web server advisory that was originally published on October 25, 2021.

TCP/IP Vulnerability Report - Forescout published an overview report on the recent spate of TCP/IP stack vulnerability reports.

For more details on these advisories and updates, including links to 3rd party reports, researcher reports and exploits, see my article at CSFN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11 - subscription required.

Tuesday, August 17, 2021

Review – 3 Advisories and 1 Update Published – 8-17-21

 Today CISA’s NCCIC-ICS published three control system security advisories for products from xArrow, Advantech, and ThroughTek. They also updated an advisory for products for multiple RTOS.

xArrow Advisory - This advisory describes three vulnerabilities in the xArrow SCADA/HMI.

Advantech Advisory - This advisory describes an improper authentication vulnerability in the Advantech WebAccess network management system (NMS).

ThroughTek Advisory - This advisory describes an improper access control vulnerability in their Kalay P2P software development kit (SDK).

Multiple RTOS Update - This update provides additional information for an advisory that was originally published on April 29th, 2021 and most recently updated on May 20th, 2021.

NOTE: CISA’s National Cyber Awareness System (NCAS) published a separate advisory for the BlackBerry BadAlloc vulnerabilities covered in this Update.

 

For more details about these advisories, including links to proof-of-concept code and plenty of editorial notes, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-published - subscription required.

Thursday, September 19, 2019

1 Advisory and 2 Updates Published – 09-19-19


Today the DHS NCCIC-ICS published one control system security advisory for products from Tridium and updates to two previously published advisories for products from WECON and Rockwell.

Tridium Advisory


This advisory describes two third-party vulnerabilities in the Tridium Niagara product. The vulnerabilies are in the Blackberry QNX operating system. The vulnerabilities were reported by Johannes Eger and Fabian Ullrich of Secure Mobile Networking Lab, and Francisco Tacliad. Tridium has updates that mitigate the vulnerabilities. There is no indication that the researchers have been provided the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

Information exposure - CVE-2019-8998; and
Improper authorization - CVE-2019-13528

NCCIC-ICS reported that a relatively low-skilled attacker with local access could exploit the vulnerabilities to allow a local user to escalate their privileges.

NOTE: Blackberry has published an advisory on the first vulnerability.

WECON Update


This update provides additional information on an advisory that was originally published on February 5th, 2019. The new information includes updated affected versions and mitigation information.

Rockwell Update


This update provides additional information on an advisory that was originally published on August 1st, 2019 and then updated on 09-05-19. The new information is the addition of a new vulnerability; access of uninitialized pointer - CVE-2019-13527.

NOTE: The updated Rockwell security advisory reports that  kimiya of 9SG Security Team has reported 7 additional vulnerabilities, bringing the total to 15 for the Rockwell Arena Simulation Software.



 
/* Use this with templates/template-twocol.html */