Showing posts with label Elber. Show all posts
Showing posts with label Elber. Show all posts

Saturday, August 31, 2024

Review – Public ICS Disclosures – Week of 8-24-24

This week we have 21 vendor advisories from Beckhoff (4), B&R, Dassault Systèmes (4), Elecom (2), Hitachi, Hitachi Energy, HP (2), Meinberg, Panasonic, TRUMPF (2), and Wireshark. There are also eight vendor updates from B&R, Dell, Elecom (5), and Moxa. Finally, we have five exploits for products from Aruba and Elber (4).

Advisories

Beckhoff Advisory #1 - CERT-VDE published an advisory that describes a cross-site scripting vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #2 - CERT-VDE published an advisory that describes an authentication bypass by alternate path or channel vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #3 - CERT-VDE published an advisory that describes a classic buffer overflow vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #4 - CERT-VDE published an advisory that describes an allocation of resources without limit or throttling vulnerability in the Beckhoff TwinCAT/BSD-based products.

B&R Advisory - B&R published an advisory that describes three vulnerabilities in their  APROL condition monitoring software.

Dassault Systèmes  Advisory #1 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their ENOVIA Collaborative Industry Innovator.

Dassault Systèmes  Advisory #2 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DSwym in 3DSwymer.

Dassault Systèmes  Advisory #3 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DDashboard in 3DSwymer.

Dassault Systèmes  Advisory #4 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DDashboard in 3DSwymer.

Elecom Advisory #1 - JP-CERT published an advisory that describes four vulnerabilities in the Elecom wireless LAN routers and access points.

Elecom Advisory #2 - JP-CERT published an advisory that describes three vulnerabilities in the Elecom wireless LAN routers.

Hitachi Advisory - Hitachi published an advisory that describes an authentication bypass vulnerability in their Ops Center Common Services product.

Hitachi Energy Advisory - Hitachi Energy published an advisory that describes an SQL injection vulnerability in their MicroSCADA X SYS600 product.

HP Advisory #1 - HP published an advisory that discusses two vulnerabilities in their Z4, Z6, and Z8 workstations.

HP Advisory #2 - HP published an advisory that discusses an incorrect default permissions vulnerability in their notebook PC’s.

Meinberg Advisory - Meinberg published an advisory that discusses three vulnerabilities (all with publicly available exploits) in their LANTIME product.

Panasonic Advisory - JP-CERT published an advisory that describes a stack-based buffer overflow vulnerability in the Panasonic Control FPWIN Pro7.

Trumpf Advisory #1 - CERT-VDE published an advisory that discusses the regreSSHion vulnerability.

Trumpf Advisory #2 - CERT-VDE published an advisory that discusses a use after free vulnerability (listed in the CISA Known Exploited Vulnerability Catalog) in the Trumpf TruControl laser control software products.

Wireshark Advisory - Wireshark published an advisory that describes an out-of-bounds read vulnerability in their NTLMSSP dissector.

Updates

B&R Updates - B&R published an update for their Automation Runtime advisory that was originally published on August 9th, 2024.

Dell Update - Dell published an update for their Dell ThinOS advisory that was originally published on June 12th, 2024, and most recently updated on July 19th, 2024.

Elecom Update #1 - JP-CERT published an update for their ELECOM and LOGITEC network devices advisory that was originally published on August 10th, 2024.

Elecom Update #2 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on July 30th, 2024.

Elecom Update #3 - JP-CERT published an update for their wireless LAN routers and wireless LAN repeater advisory that was originally published on March 26th, 2024 and most recently updated on May 28th, 2024.

Elecom Update #4 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on March 26th, 2024 and most recently updated on May 28th, 2024.

Elecom Update #5 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on May 28th, 2024.

Moxa Update - Moxa published an update for their regreSSHion advisory that was originally published on August 2nd, 2024, and most recently updated on August 9th, 2024.

Exploits

Aruba Exploit - Hosein Vita published an exploit for a remote code execution vulnerability in the Aruba 501 CN12G5W0XX wireless access point.

Elber Exploit #1 - LiquidWorm published an exploit for an authentication bypass vulnerability in the Elber ESE DVB-S/S2 Satellite Receiver.

Elber Exploit #2 - LiquidWorm published an exploit for a device configuration vulnerability in the Elber ESE DVB-S/S2 Satellite Receiver.

Elber Exploit #3 - LiquidWorm published an exploit for an authentication bypass vulnerability in the Elber Wayber Analog/Digital Audio.

Elber Exploit #4 - LiquidWorm published an exploit for a device configuration vulnerability in the Elber Wayber Analog/Digital Audio.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, as well as a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-631 - subscription required.

Saturday, May 11, 2024

Review – Public ICS Disclosures – Week of 5-4-24

This week we have 12 vendor disclosures from Aruba Networks, CODESYS, Honeywell, HP, Moxa, SEL (4), Socomec, and Westermo (2). There are also two vendor updates from Broadcom and HP. Eleven researcher reports are available for vulnerabilities in products from Dassault Systèmes (11). Finally, we have six exploits for products from Elber.

Advisories

Aruba Advisory - Aruba published an advisory that discusses the Terrapin-Attack vulnerability.

CODESYS Advisory - CODESYS published an advisory that describes two vulnerabilities in their Development System V2.3 products.

Honeywell Advisory - Honeywell Advisory published an end-of-life notice for their Pro-Watch 5.0 product.

HP Advisory - HP published an advisory that discusses an uncontrolled resource consumption vulnerability in their Teradici PCoIP Management Console.

Moxa Advisory - Moxa published an advisory that describes a cross-site scripting vulnerability in their NPort 5100A series products.

SEL Advisory #1 - SEL published an advisory that announced that the latest version of their Blueframe OS fixed three cybersecurity issues.

SEL Advisory #2 - SEL published an advisory that announced that the most recent SEL-3350-1 BIOS update fixed 10 vulnerabilities (nine of which have available exploits).

SEL Advisory #3 - SEL published an advisory that announced that the latest update for their SEL-3355-2/SEL-3360-2 Intel Management Engine included fixes for two vulnerabilities.

SEL Advisory #4 - SEL published an advisory that announced that the most recent SEL-3355-2/SEL-3360-2 BIOS update fixed 10 vulnerabilities (nine of which have available exploits).

Socomec Advisory - INCIBE-CERT published an advisory that describes two vulnerabilities in the Socomec NET VISION 7, UPS WEB/SNMP Ethernet Card.

Westermo Advisory #1 - Westermo published an advisory that describes four vulnerabilities in their EDW-100 serial to Ethernet converter.

Westermo Advisory #2 - Westermo published an advisory that describes a cleartext transmission of sensitive information vulnerability in their WeOS.

Updates

Broadcom Update - Broadcom published an update for their SANnav exposes Kafka advisory that was originally published on April 25th, 2024 and most recently updated on April 30th, 2024.

HP Update - HP published an update for their Plantronics Hub advisory that was originally published on December 20th, 2023.

Researcher Reports

Dassault Reports - The Zero Day Initiative published eleven reports for individual vulnerabilities in the Dassault Systèmes eDrawings Viewer.

Exploits

Elber Exploits - LiquidWorm published six exploits for vulnerabilities in three products from Elber.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-89b - subscription required.

 
/* Use this with templates/template-twocol.html */