Showing posts with label Cyber Danube. Show all posts
Showing posts with label Cyber Danube. Show all posts

Saturday, July 27, 2024

Review – Public ICS Disclosures – Week of 7-20-24

This week we have two CrowdStrike outage advisories. We also have 18 other vendor advisories for products from Broadcom, Draeger, Hitachi, HPE (4), Meinberg, National Instruments (7), WithSecure (2), and Zyxel. We have three vendor updates from Cisco (2) and HP. There is also a researcher report for vulnerabilities in products from Perkin Elmer. Finally, we have an exploit for products from Softing.

CrowdStrike Outage

GE Vernova published an advisory that discussed the impact on some of their Monitoring & Diagnostics products.

Philips published an advisory that provides a list of potentially affected products.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses ten vulnerabilities in the Azul Zulu component of their Brocade SANnav product.

Draeger Advisory - Draeger published an advisory that discusses a deserialization of untrusted data vulnerability (listed in the CISA Known Exploited Vulnerability Catalog).

Hitachi Advisory - Hitachi published an advisory that discusses 27 vulnerabilities in their Disk Array Systems.

HPE Advisory #1 - HPE published an advisory that describes three vulnerabilities in their Aruba EdgeConnect SD-WAN Orchestrator.

HPE Advisory #2 - HPE published an advisory that discusses 21 vulnerabilities (6 with known exploits) in their Unified OSS Console Assurance Monitoring (UOCAM) product.

HPE Advisory #3 - HPE published an advisory that discusses seven vulnerabilities (one with known exploit) in their Aruba EdgeConnect SD-WAN Gateways.

HPE Advisory #4 - HPE published an advisory that discusses an out-of-bounds write vulnerability in their ProLiant DL/ML/SY/XL and Alletra Servers.

Meinberg Advisory - Meinberg published an advisory that discusses ten vulnerabilities (2 with known exploits) in their Lantime product.

National Instruments Advisory #1 - National Instruments published an advisory that describes two missing authorization vulnerabilities in their VeriStand Gateway product.

National Instruments Advisory #2 - National Instruments published an advisory that describes two deserialization of untrusted data vulnerabilities in their VeriStand product.

National Instruments Advisory #3 - National Instruments published an advisory that describes a path traversal vulnerability in their VeriStand product.

National Instruments Advisory #4 - National Instruments published an advisory that describes a deserialization of untrusted data vulnerability in their VeriStand Project File product.

National Instruments Advisory #5 - National Instruments published an advisory that describes an integer overflow or wraparound vulnerability in their TDMS Files in LabVIEW.

National Instruments Advisory #6 - National Instruments published an advisory that describes an incorrect default permissions vulnerability in their SystemLink Redis Service.

National Instruments Advisory #7 - National Instruments published an advisory that describes an out-of-date component with multiple vulnerabilities vulnerability in their SystemLink Server.

WithSecure Advisory #1 - WithSecure published an advisory that describes a denial of service vulnerability in their WithSecure Mac antivirus software.

WithSecure Advisory #2 - WithSecure published an advisory that describes a privilege escalation vulnerability in their WithSecure Mac Products.

Zyxel Advisory - Zyxel published an advisory that describes an improper privilege management vulnerability in their Zyxel AP products.

Updates

Cisco Update #1 - Cisco published an update for their Blast-Radius advisory that was originally published on July 10th, and most recently updated on July 19th, 2024.

Cisco Update #2 - Cisco published an update for their regreSSHion advisory that was originally published on July 2nd, 2024, and most recently updated on July 19th, 2024.

HP Update - HP published an update for their Display Control Software advisory that was originally published on July 15th, 2024.

Researcher Reports

Perkin Elmer Report - Cyber Danube published a report that describes three vulnerabilities in the Perkin Elmer ProcessPlus measurement software.

Exploits

Softing Exploit - Mr me published a Metasploit module for two vulnerabilities in the Softing Secure Integration Server.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-d58 - subscription required.

Sunday, May 14, 2023

Review – Public ICS Disclosures – Week of 5-6-23 – Part 2

For Part 2 this week we have four additional vendor disclosures from Schneider. We also have 18 updates for products from Schneider (2) and Siemens (16). There are three researcher reports for products from Advantech and Weston (2).

Advisories

Schneider Advisory #1 - Schneider published an advisory that describes an improper XML external entity reference vulnerability in their OPC Factory Server.

Schneider Advisory #2 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power Operation, EcoStruxure Power SCADA Operation products.

Schneider Advisory #3 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power Operation, EcoStruxure Power SCADA Operation products.

Schneider Advisory #4 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power SCADA Anywhere products.

Updates

Schneider Update #1 - Schneider published an update for their INFRA:HALT advisory that was originally published on February 8th, 2022, and most recently updated on February 14th, 2023.

Schneider Update #2 - Schneider published an update for their BadAlloc advisory that was originally published on April 12th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #1 - Siemens published an update for their SIPROTEC 5 devices advisory that was originally published on April 11th, 2023.

Siemens Update #2 - Siemens published an update for their Siemens Industrial Products using Intel CPUs advisory that was originally published on August 10th, 2021 and most recently updated on December 13th, 2022.

Siemens Update #3 - Siemens published an update for their TIA Portal advisory that was originally published on April 11th, 2023.

Siemens Update #4 - Siemens published an update for their SIMATIC S7-400 CPUs advisory that was originally published on November 13th, 2018 and most recently updated on January 10th, 2023.

Siemens Update #5 - Siemens published an update for their OpenSSL Affecting Industrial Products advisory that was originally published on June 14th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #6 - Siemens published an update for their Siemens Industrial Products using Intel CPUs advisory that was originally published on February 14th, 2023.

Siemens Update #7 - Siemens published an update for their TIA Project-Server advisory that was originally published on February 14th, 2023.

Siemens Update #8 - Siemens published an update for their Polarion ALM advisory that was originally published on April 11th, 2014.

Siemens Update #9 - Siemens published an update for their Industrial Products advisory that was originally published on March 20th, 2018 and most recently updated on April 11th, 2023.

Siemens Update #10 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 11th, 2023.

Siemens Update #11 - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022.

Siemens Update #12 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 9th, 2019.

Siemens Update #13 - Siemens published an update for their e Web Server Login Page of Industrial Controllers advisory that was originally published on November 8th, 2022 and most recently updated on April 11th, 2023.

Siemens Update #14 - Siemens published an update for their Profinet Devices advisory that was originally published on October 8th, 2018, and most recently update on January 10th, 2023.

Siemens Update #15 - Siemens published an update for their Industrial Products advisory that was originally published on December 13th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #16 - Siemens published an update for their n Industrial Real-Time (IRT) Devices advisory that was originally published on October 8th, 2019, and most recently updated on April 11th, 2023.

Researcher Reports

Advantech Report - Cyber Danube published a report about three vulnerabilities in the Advantech EKI-1524-CE series, EKI-1522 series, EKI-1521 series serial device servers.

Weston Reports - Cisco Talos published two reports about three vulnerabilities in the Weston Embedded uC-FTPs.

 

For more details on these disclosures, including a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-e8f - subscription required.

 
/* Use this with templates/template-twocol.html */