Showing posts with label Commend. Show all posts
Showing posts with label Commend. Show all posts

Saturday, May 4, 2024

Review – Public ICS Disclosures – Week of 4-27-24

This week we have 13 vendor disclosures from Aruba Networks, Commend (5), Hitachi Energy (3), HP, HPE, Moxa, and Philips. There is one vendor update this week from Palo Alto Networks. Finally, we have three researcher reports for vulnerabilities in products from Merative Merge.

Advisories

Aruba Advisory - Aruba published an advisory that describes ten vulnerabilities in their ArubaOS.

Commend Advisory #1 - Commend published an advisory that describes an improper authentication vulnerability in their Symphony MX web server.

Commend Advisory #2 - Commend published an advisory that discusses 18 vulnerabilities (7 with known exploits) in their VirtuoSIS, S3 and S6 products.

Commend Advisory #3 - Commend published an advisory that describes multiple vulnerabilities in their VirtuoSIS, S3 and S6.

Commend Advisory #4 - Commend published an advisory that describes multiple vulnerabilities in their VirtuoSIS, S3 and S6.

Commend Advisory #5 - Commend published an advisory that discusses the  Terrapin-Attack vulnerability.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes two vulnerabilities in their SDM600 series product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes a secure update bypass vulnerability in their RTU500 series product.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that discusses nine vulnerabilities (two with known exploits) in their Tropos Mesh Routers.

HP Advisory - The HP Security Bulletins page lists an advisory for “HP Application Enabling Software Driver - Privileged File Overwrite” but the link currently takes one to a blank error page.

HPE Advisory - HPE published an advisory that discusses two vulnerabilities in their OneView software. These are third-party vulnerabilities.

Moxa Advisory - Moxa published an advisory that discusses the XZ Containing Malware/Backdoor vulnerability.

Philips Advisory - Philips published an advisory that discusses the Cisco ArcaneDoor vulnerabilities.

Updates

Palo Alto Networks Update - Palo Alto Networks published an update for their Arbitrary File Creation advisory that was originally published on April 12th, 2024 and most recently updated on April 24th, 2024.

Researcher Reports

Merative Merge Reports - Nozomi Networks published three reports of individual vulnerabilities in the Merative Merge DICOM product.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-c86 - subscription required.

Saturday, March 9, 2024

Review – Public ICS Disclosures – Week of 3-2-24

This week we have 12 vendor disclosures from Aruba Networks, Commend, Moxa, Omron, QNAP (5), SEL, VMware (2), and Western Digital. There are four vendor updates from Cisco and HP (3). We also have three researcher reports of vulnerabilities for products from Lenovo. Finally, we have five exploits for Petrol Pump (3), RAD, and Solar-Log.

Advisories

Aruba Advisory - Aruba published an advisory that describes seven vulnerabilities in their ArubaOS products.

Commend Advisory - Commend published an advisory that describes three vulnerabilities in their WS-TM monitor firmware.

Moxa Advisory - Moxa published an advisory that describes a stack-based buffer overflow vulnerability in their NPort W2150A/W2250A Series web server.

Omron Advisory - Omron published an advisory that describes a path traversal vulnerability in their NJ/NX-series Machine

Automation Controllers.-

QNAP Advisory #1 - QNAP published an advisory that describes a path traversal vulnerability in their Photo Station product.

QNAP Advisory #2 - QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes a cross-site scripting vulnerability in their Network & Virtual Switch products.

QNAP Advisory #4 - QNAP published an advisory that discusses four vulnerabilities in their QuMagie Mobile 2.2.x for Android product.

QNAP Advisory #5 - QNAP published an advisory that describes three vulnerabilities in their QTS, QuTS hero, QuTScloud, and myQNAPcloud products.

SEL Advisory - SEL published an announcement that the latest version of their SEL-5030 acSELerator QuickSet Software addresses a number of undescribed cybersecurity issues.

VMware Advisory #1 - VMware published an advisory that describes four vulnerabilities in their ESXi, Workstation, and Fusion products.

VMware Advisory #2 - VMware published an advisory that describes a partial information disclosure vulnerability in their VMware Cloud Director product.

Western Digital Advisory - Western Digital published an advisory that describes a DLL hijacking vulnerability in their SanDisk PrivateAccess product.

Updates

Cisco Update - Cisco published an update for their cURL advisory that was originally published on October 12th, 2023 and most recently updated on February 21st, 2024.

HP Update #1 - HP published an update for their UC software advisory that was originally published on January 9th, 2024.

HP Update #2 - HP published an update for their UC software advisory that was originally published on January 8th, 2024.

HP Update #3 - HP published an update for their UC Software advisory that was originally published on January 9th, 2023 and most recently updated on February 9th, 2024.

Researcher Reports

Lenovo Report #1 - Binarly published a report describing an unsanitized arguments vulnerability in the Lenovo J1CN38WW.

Lenovo Report #2 - Binarly published a report describing an out-of-bounds write vulnerability in the Lenovo J1CN38WW.

Lenovo Report #3 - Binarly published a report describing an out-of-bounds write vulnerability in the Lenovo J1CN38WW.

Exploits

Petrol Pump Exploit #1 - Shubham Pandey published an exploit for two cross-site scripting vulnerabilities in the Petrol Pump management software.

Petrol Pump Exploit #2 - Shubham Pandey published an exploit for an SQL injection vulnerability in the Petrol Pump management software.

Petrol Pump Exploit #3 - Shubham Pandey published an exploit for a shell upload vulnerability in the Petrol Pump management software.

RAD Exploit - Branko Milicevic published an exploit for a directory traversal vulnerability in the RAD SecFlow-2 devices.

Solar-Log Exploit - Mesut Cetin published an exploit for a cross-site scripting vulnerability in the Solar-Log 200 PM+ product.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-205  - subscription required.

Tuesday, February 20, 2024

Review – 3 Advisories Published – 2-20-24

Today, CISA’s NCCIC-ICS published three control system security advisories for products from Mitsubishi Electric, CISA and Commend.

Advisories

Mitsubishi Advisory - This advisory discusses an improper input validation vulnerability in the Mitsubishi Electrical discharge machines.

CISA Advisory - This advisory describes two vulnerabilities in the CISA Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin.

Commend Advisory - This advisory describes three vulnerabilities in the Commend WS203VICM video door station.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-2-20-24 - subscription required.

 
/* Use this with templates/template-twocol.html */