Showing posts with label DrayTek. Show all posts
Showing posts with label DrayTek. Show all posts

Monday, October 7, 2024

Reader Comment – DrayTek Advisories

Earlier today an anonymous reader left a comment on my Saturday ‘Public ICS Disclosure’ blog post pointing out a mistake in my reporting on the second DrayTek advisory. I had reported that the advisory described “seven classic buffer overflow vulnerabilities in multiple Vigor routers”. As the anonymous commentor noted, the number should have been 16 not seven. My mistake arose because of the way that I read the advisory listing of the vulnerabilities:

“The Buffer Overflow Vulnerabilities have been discovered, which could potentially allow an authenticated attackers to cause a Denial of Service (DoS) via a crafted input. The vulnerabilities have been announced under CVE-2024-46550 CVE-2024-46568, CVE-2024-46571, CVE-2024-46580 CVE-2024-46586, CVE-2024-46588 ~ CVE-2024-46598.”

The highlighted ‘~’ is what I overlooked. To be fair, DrayTek used the same convention for listing consecutive CVE’s in their first advisory and I caught their meaning there, I just missed it here. Mea Culpa. And many thanks to the anonymous commentor for catching that error.

Looking at the NVD.NIST.gov listings for all 16 CVE’s, these are all ‘Classic Buffer Overflow’ vulnerabilities. The CNA for the CVE’s are all listed as ‘MITRE’ with a publication date of September 18th, 2024. They were apparently reported to Mitre by the researcher as the only link provided on the CVE record is to variations to “(https)://ink-desk-28f.notion.site/Draytek-vigor-3910-Analysis-Report-XXXX” where the ‘XXXX’ is a unique alpha-numeric string for each CVE. Access to the linked sites is restricted. The CVE record does list the parameter and file where the unique buffer overflow occurs.

Saturday, October 5, 2024

Review – Public ICS Disclosures – Week of 9-28-24

This week we have 13 vendor disclosures from Bosch (2), Cisco, DrayTek (2), Hitachi, HP, JTEKT, QNAP, SEL (2), Splunk, Westermo, and WithSecure. We have two vendor updates from Dell. Finally, we have two exploits for products from ABB and Blackberry.

Advisories

Bosch Advisory #1 - Bosch published an advisory that describes a sensitive information disclosure vulnerability in their Configuration Manager.

Bosch Advisory #2 - Bosch published an advisory that discusses three vulnerabilities in their PRC7000 product.

Cisco Advisory - Cisco published an advisory that describes two vulnerabilities in their Small Business Dual WAN Gigabit VPN Routers.

DrayTek Advisory #1 - DrayTek published an advisory that describes 14 vulnerabilities (with exploits available) in multiple Vigor routers.

DrayTek Advisory #2 - DrayTek published an advisory that describes seven classic buffer overflow vulnerabilities in multiple Vigor routers.

Hitachi Advisory - Hitachi published an advisory that discusses an improper input validation vulnerability in their Cosminexus Component Container.

HP Advisory - HP published an advisory that describes an escalation of privilege vulnerability in their business notebook PCs.

QNAP Advisory - QNAP published an advisory that discusses the CUPS vulnerabilities.

SEL Advisory #1 - SEL published a new version notice for their SEL-5030 acSELerator QuickSet Software that includes a description of a cybersecurity enhancement.

SEL Advisory #2 - SEL published a new version notice for their SEL-5813 Backup and Recovery Tool (BaRT) that includes a description of a cybersecurity enhancement.

Splunk Advisory - Splunk published an advisory that discusses four vulnerabilities in their Add-on for Amazon Web Services.

Westermo Advisory - Westermo published an advisory that describes a session hijacking vulnerability in their IbexOS Web Interface.

WithSecure Advisory - WithSecure published an advisory that describes a denial-of-service vulnerability in their Atlant Product.

Updates

Dell Update #1 - Dell published an update for their ThinOS advisory that was originally published on September 9th, 2024, and most recently updated on September 18th, 2024. The

Dell Update #2 - Dell published an update for their ThinOS advisory that was originally published on June 12th, 2024, and most recently updated on September 9th, 2024.

Exploits

ABB Exploit - LiquidWorm published an exploit for a file disclosure vulnerability in the ABB Cylon Aspect.

Blackberry Exploit - SEC Consult published an exploit for an uninstall password bypass vulnerability in the Blackberry CylanceOPTICS product.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-d4d - subscription required.

Saturday, September 16, 2023

Review – Public ICS Disclosures – Week of 9-9-23 – Part 1

For the week of Cyber Tuesday, the number of disclosures is very reasonable. Still, I am doing a two-part post. For Part 1 we have 16 vendor disclosures for DrayTek, FortiGuard, HP, HPE (2), Insyde (2), JTEKT, Palo Alto Networks (2), QNAP (3), Rockwell Automation (2), and Trumpf. There is one vendor update from Broadcom.

For Part 2 I will be looking at advisories and updates from Schneider and Siemens as well as four exploits.

Advisories

DrayTek Advisory - DrayTek published an advisory that describes a format string vulnerability in their Vigor routers.

FortiGuard Advisory - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiProxy and FortiOS products.

HP Advisory - HP published an advisory that discusses two vulnerabilities in multiple products.

HPE Advisory #1 - HPE published an advisory that describes two authentication bypass vulnerabilities in their OneView infrastructure management software.

HPE Advisory #2 - HPE published an advisory that discusses the Downfall Attacks vulnerability.

Insyde Advisory #1 - Insyde published an advisory that discusses four vulnerabilities in their InsydeH2O product.

Insyde Advisory #2 - Insyde published an advisory that describes an arbitrary code execution vulnerability in their SystemFirmwareManagementRuntimeDxe.

JTEKT Advisory - JTEKT published an advisory that describes two vulnerabilities in their Kostac PLC Programming Software.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes an improper handling of exceptional conditions vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses an improper validation of integrity check value vulnerability in their PAN-OS and Prisma products.

QNAP Advisory #1 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #2 - QNAP published an advisory that describes two NULL pointer dereference vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes two out-of-bounds write vulnerabilities in their QTS, QuTS hero and QuTScloud products.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their FactoryTalk View Machine Edition product.

Rockwell Advisory #2 - Rockwell published an advisory that discusses four vulnerabilities in their KEPServerEX product.

Trumpf Advisory - CERT-VDE published an advisory that discusses two vulnerabilities in the TRUMPF License Expert.

Updates

Broadcom Update - Broadcom published an update for their use-after-free advisory that was originally published on August 1st, 2023.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-900 - subscription required.

Saturday, March 11, 2023

Review – Public ICS Disclosures – Week of 3-4-23

This week we have 26 vendor disclosures from ABB, Apache, DrayTek, FortiGuard Labs (15), GE Grid Solutions, Hitachi, HPE (2), Insyde, Mitsubishi, Moxa, and Phoenix Contact. And we have two exploits for products from Real Time Automation and AgileBio.

Advisories

ABB Advisory - ABB published an advisory that discusses an improper input validation vulnerability in their Substation management unit COM600.

Apache Advisory - Apache announced a memory exhaustion vulnerability in unsupported versions of Apache Log4j.

DrayTek Advisory - DrayTek published an advisory that describes a cross-site scripting vulnerability in their Vigor routers.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an incomplete filtering of one or more instances of special elements vulnerability in their FortiWeb and FortiRecorder.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiWeb products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes an access control vulnerability in their FortiSOAR's playbook.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes an uncontrolled resource consumption vulnerability in their FortiRecorder products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #6 - FortiGuard published an advisory that describes a path traversal vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #7 - FortiGuard published an advisory that describes a buffer underwrite vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #8 - FortiGuard published an advisory that describes a path traversal vulnerability in their FortiOS products.

FortiGuard Advisory #9 - FortiGuard published an advisory that describes an access of an unitialized pointer vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #10 - FortiGuard published an advisory that describes an improper privilege management vulnerability in their FortiNAC products.

FortiGuard Advisory #11 - FortiGuard published an advisory that describes a reflected cross-site scripting vulnerability in their FortiNAC products.

FortiGuard Advisory #12 - FortiGuard published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their FortiManager, FortiAnalyzer, FortiPortal and FortiSwitch products.

FortiGuard Advisory #13 - FortiGuard published an advisory that describes an improper restriction of excessive authorization attempts vulnerability in their FortiAuthenticator, FortiDeceptor and FortiMail products.

FortiGuard Advisory #14 - FortiGuard published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their FortiAnalyzer products.

FortiGuard Advisory #15 - FortiGuard published an advisory that describes an improper neutralization of formula elements vulnerability in their FortiAnalyzer products.

GE Advisory - GE Grid Solutions published an advisory for their Reason S20 products.

Hitachi Advisory - Hitachi published an advisory that discusses 36 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities.

HPE Advisory #1 - HPE published an advisory that describes a host head injection vulnerability in their FlexFabric 5700 Switches.

HPE Advisory #2 - HPE published an advisory that describes an information disclosure vulnerability in their Superdome Flex and Superdome Flex 280 Servers.

Insyde Advisory - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in multiple products.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses two classic buffer overflow vulnerabilities in their GENESIS64 product.

Moxa Advisory - Moxa published an advisory [added link - 5-25-23 1330 EDT] that describes two vulnerabilities in their MXsecurity series.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses two vulnerabilities in their TC ROUTER and CLOUD CLIENT.

Exploits

Real Time Automation Exploit - Yehia Eighaly published an exploit for a cross-site scripting vulnerability in the Real Time Automation 460MCBS - Modbus TCP to BACnet/IP Gateway.

AgileBio Exploit – Anthony Cole published an exploit for a remote code execution vulnerability in the AbileBio LabCollector LIMS system.


For more details on these disclosures, including links to third-party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-07f - subscription required.


Saturday, August 6, 2022

Review – Public ICS Disclosures – Week of 7-30-22

This week we have eleven vendor disclosures from Belden, Bosch, DrayTek, HPE, Meinberg, Mitsubishi, OPC Foundation, PulseSecure, Software Toolbox (2), and VMware. There are also two updates from Belden and HP.

 

Belden Advisory - Belden published an advisory that describes a denial of service vulnerability in their Hirschmann EagleSDV.

Bosch Advisory - Bosch published an advisory that describes two vulnerabilities in the their BF-OS. Bosch

DrayTek Advisory - DrayTek published an advisory that describes a remote code execution vulnerability in their Vigor Routers.

NOTE: The DrayTek advisory includes an actual link to the Trellix report. That is full disclosure.

HPE Advisory - HPE published an advisory that discusses a directory traversal vulnerability in their B-series Fibre Channel SAN Switch.

Meinberg Advisory - Meinberg published an advisory that discusses fifteen vulnerabilities (13 with available exploits) in their LANTIME firmware.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses two vulnerabilities in their GT SoftGOT2000.

NOTE: The Mitsubishi advisory notes that these vulnerabilities affect “multiple FA products”, but only one product is currently listed. We may see additional products added in future updates.

OPC Foundation - The OPC Foundation published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their OPC UA .NET Standard Reference Server.

PulseSecure Advisory - PulseSecure published an advisory that discusses an OS command injection vulnerability.

Software Toolbox Advisory #1 - Software Toolbox published an advisory that discusses the DICOM hardening vulnerability in their OPC Quick Client.

Software Toolbox Advisory #2 - Software Toolbox published an advisory that discusses the DICOM hardening vulnerability in their Top Server.

VMware Advisory - VMware published an advisory that describes ten vulnerabilities (with one known exploit) in multiple products.

Belden Update - Belden published an update for their FragAttacks advisory that was originally published on March 14th, 2022.

HP Update - HP published an update for their Wireless Bluetooth advisory that was originally published on February 8th, 2022 and most recently updated on June 13th, 2022.

 

For more details on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-ec0 - subscription required.

Saturday, April 30, 2022

Review – Public ICS Disclosures – Week of 4-23-22 – Part 1 -

This is another busy week necessitating two-part coverage. In part 1 this week we have nineteen vendor disclosures from ABB, Bender, Bosch, Braun (2), DrayTek, Eaton (5), HPE, Meile, PEPPERL+FUCHS, Philips (2), and Pilz (3).

ABB Advisory - ABB published an advisory discussing six vulnerabilities in their AC 500 PLCs.

Bender Advisory - CERT-VDE published an advisory describing seven vulnerabilities in the Bender/ebee Charge Controller products.

Bosch Advisory - Bosch published an advisory discussing an infinite loop vulnerability in their FL MGUARD and TC MGUARD safety devices.

Braun Advisory #1 - Braun published an advisory discussing the NAME:WRECK vulnerabilities.

Braun Advisory #2 - Braun published an advisory discussing the Amnesia:33 vulnerabilities.

DrayTek Advisory - DrayTek published an advisory discussing an infinite loop vulnerability in their Vigor routers.

Eaton Advisory #1 - Eaton published an advisory discussing TLStorm vulnerabilities and the Havex trojan as being used by the Berserk Bear APT group against UPS systems.

Eaton Advisory #2 - Eaton published an advisory discussing the SpringShell vulnerabilities.

Eaton Advisory #3 - Eaton published an advisory discussing sixteen vulnerabilities (six with known exploits) in their Form 7 recloser control. These are third-party (CODESYS) vulnerabilities.

Eaton Advisory #4 – Eaton published an advisory discussing the INCONTROLLER ICS attack tools.

Eaton Advisory #5 - Eaton published an advisory discussing the TLStorm vulnerabilities.

HPE Advisory - HPE published an advisory discussing three vulnerabilities (one with known exploits) in their SimpliVity Omnistack for Hyper-V.

Meile Advisory - CERT-VDE published an advisory describing an improper privilege management vulnerability (with publicly available exploit) in their Benchmark Programming Tool.

PEPPERL+FUCHS Advisory - CERT-VDE published an advisory discussing a remote code execution vulnerability in VisuNet devices from PEPPERL+FUCHS.

Philips Advisory #1 - Philips published an advisory discussing a remote code execution vulnerability.

Philips Advisory #2 - Philips published an advisory discussing a denial of service vulnerability.

Pilz Advisory #1 - CERT-VDE published an advisory discussing ten vulnerabilities (one with publicly available exploit) in the Pilz PMC programming tool.

Pilz Advisory #2 - CERT-VDE published an advisory discussing 27 vulnerabilities (nine with publicly available exploits) in the Pilz PMC programming tool.

Pilz Advisory #3 - CERT-VDE published an advisory discussing 18 vulnerabilities (four with publicly available exploits) in motion controller products from Pilz.

 

For more details on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-bda - subscription required.

Saturday, October 16, 2021

Review - Public ICS Disclosures – Week of 10-9-21 – Part 1

This week we have nine vendor disclosures from Aruba Networks, Braun, DrayTek, Omron, Hitachi, SonicWall, and VMware (3). We also have an update from Yokogawa. Finally, there are four researcher reports for products from Fuji Electric.

Aruba Advisory - Aruba published an advisory describing 18 vulnerabilities in their ClearPass Policy Manager product.

Braun Advisory - Braun published an advisory discussing the Ripple20 vulnerabilities.

DrayTek Advisory - DrayTek published an advisory describing two vulnerabilities in their VigorConnect software.

Omron Advisory - JPCERT published an advisory describing an out-of-bounds read vulnerability in the Omron CX-Supervisor.

Hitachi Advisory - Hitachi published an advisory discussing 30 vulnerabilities in their Disk Array Systems.

SonicWall Advisory - SonicWall published an advisory describing a host header redirection vulnerability in their SonicOS product.

VMware Advisory #1 - VMware published an advisory describing a server side request forgery in their vRealize Operations products.

VMware Advisory #2 - VMware published an advisory describing a CSV injection vulnerability in their vRealize Log Insight product.

VMware Advisory #3 - VMware published an advisory describing an open redirect vulnerability in their vRealize Orchestrator product.

Yokogawa Update - Yokogawa published an update for their Ripple20 advisory that was originally published on May 31st, 2021.

Fuji Reports - The Zero Day Initiative published four reports of 0-day vulnerabilities in the Alpha5 Servo Operator product from Fuji Electric.

For more details on this disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-61d - subscription required.


 
/* Use this with templates/template-twocol.html */