Showing posts with label Eurotech. Show all posts
Showing posts with label Eurotech. Show all posts

Saturday, November 4, 2023

Review – Public ICS Disclosure – Week of 10-28-23 – Part 1

This week for Part 1 we have 20 vendor disclosures from ABB, Bentley, Cisco (5), CODESYS, Eurotech, GE Grid, Hitachi (2), Hitachi Energy (2), Insyde (3), and Moxa (3).

Part 2 will include a large number of vendor updates.

Advisories

ABB Advisory - ABB published an advisory that discusses 16 vulnerabilities in their COM600 product.

Bentley Advisory - Bentley published an advisory that discusses an out-of-bounds write vulnerability in their Seequent LeapFrog product.

Cisco Advisory #1 - Cisco published an advisory that describes a policy bypass vulnerability in their Snort 3 detection engine.

Cisco Advisory #2 - Cisco published an advisory that describes an SSL/TLS certificate handling vulnerability in their Snort 3 Detection Engine.

Cisco Advisory #3 - Cisco published an advisory that describes a memory allocation vulnerability in their Snort 3 Detection Engine.

Cisco Advisory #4 - Cisco published an advisory that describes a policy bypass vulnerability in their Snort 3 detection engine.

Cisco Advisory #5 - Cisco published an advisory that describes an IP geolocation bypass vulnerability in their Snort 3 detection engine.

CODESYS Advisory - CODESYS published an advisory that discusses a heap-based buffer overflow vulnerability in a variety of CODESYS V2 and V3 products.

Eurotech Advisory - Eurotech published an advisory that discusses an unquoted search path or element vulnerability in a number of Eurotech products.

GE Grid Advisory - GE published an advisory for a vulnerability in their S1 Agile Engineering Tool Suite.

Hitachi Advisory #1 - Hitachi published an advisory that discusses 21 vulnerabilities in their Disk Array Systems products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses three vulnerabilities in their Cosminexus Developer's Kit for Java and Hitachi Developer's Kit for Java.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes three vulnerabilities in their eSOMS product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes two vulnerabilities in their MACH System software product.

Insyde Advisory #1 - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in their AsfSecureBootDxe.

Insyde Advisory #2 - Insyde published an advisory that describes an SMM memory corruption vulnerability in their CsmInt10HookSmm.

Insyde Advisory #3 - Insyde published an advisory that describes an unsanitized arguments in SMI handler vulnerability in their IhisiServicesSmm.

Moxa Advisory #1 - Moxa published an advisory that describes a classic buffer overflow vulnerability in their EDR-810/G902/G903 Series web server.

Moxa Advisory #2 - Moxa published an advisory that describes the use of a broken or risky cryptographic algorithm vulnerability in their NPort 6000 Series products.

Moxa Advisory #3 - Moxa published an advisory that discusses seven vulnerabilities in their PT-G503 Series products.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-e57 - subscription required. 

Saturday, November 12, 2022

Review – Public ICS Disclosures – Week of 11-5-22 – Part 1 -

This is a busy Saturday after the 2nd Tuesday. For Part 1 this week we have five OpenSSL 3.0 vendor disclosures from Carrier, Draeger, Eurotech, Palo Alto Networks, and QNAP.  There are 23 other vendor disclosures from Aiphone, Belden, Broadcom (9), Carrier, Fujitsu, GE Gas Power, HP, and HPE (8).

OpenSSL 3.0 Disclosures

Carrier published an OpenSSL 3.0 advisory. Carrier reports that no products are affected.

Draeger published an OpenSSL 3.0 advisory. Draeger reports that their medical devices are not affected.

Eurotech published an OpenSSL 3.0 advisory. Eurotech reports that none of their products are affected.

Palo Alto Networks updated their OpenSSL 3.0 advisory. They report that none of their products are affected.

QNAP published an OpenSSL 3.0 advisory. QNAP reports that their products are not affected.

Other Vendor Disclosures

Aiphone Advisory - Aiphone published an advisory that describes an information disclosure vulnerability in their GT Entrance Station product.

Belden Advisory - Belden published an advisory that discusses two unauthorized access vulnerabilities in their Provise and Hirschmann network management products.

Broadcom Advisory #1 - Broadcom published an advisory that discusses an off-by-one error vulnerability in their Brocade SANnav.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an infinite loop vulnerability in undisclosed products (probably Brocade SANnav).

Broadcom Advisory #3 - Broadcom published an advisory that discusses an out-of-bounds write in their Brocade SANnav product.

Broadcom Advisory #4 - Broadcom published an advisory that describes an improper storage of sensitive information vulnerability in their Brocade SANnav product.

Broadcom Advisory #5 - Broadcom published an advisory that describes an information exposure vulnerability in their Brocade SANnav product.

Broadcom Advisory #6 - Broadcom published an advisory that describes an information exposure vulnerability in their Brocade SANnav product.

Broadcom Advisory #7 - Broadcom published an advisory that describes weak key exchange vulnerability in their Brocade SANnav product.

Broadcom Advisory #8 - Broadcom published an advisory that describes an information exposure vulnerability in their Brocade SANnav product.

Broadcom Advisory #9 - Broadcom published an advisory that describes a remote code execution vulnerability in their Brocade Fabric OS.

Carrier Advisory - Carrier published an advisory that discusses the Text4Shell vulnerability.

Fujitsu Advisory - Fujitsu published an advisory that discusses eight vulnerabilities in a variety of Fujitsu products.

GE Advisory - GE Gas Power published an advisory that discusses “Malware Persistence in VMWare ESXi Hypervisor”.

HP Advisory - HP published an advisory that describes a privilege escalation vulnerability in the BIOS for a number of HP products.

HPE Advisory #1 - HPE published an advisory that discusses an authentication bypass vulnerability in their B-series SAN Switches.

HPE Advisory #2 - HPE published an advisory that discusses five vulnerabilities in their B-Series SANnav Management Portal.

HPE Advisory #3 - HPE published an advisory that discusses an improper input validation vulnerability in their Synergy Servers.

HPE Advisory #4 - HPE published an advisory that discusses two vulnerabilities in their ProLiant Moonshot Servers.

HPE Advisory #5 - HPE published an advisory that discusses six vulnerabilities in their ProLiant DL/ML Servers.

HPE Advisory #6 - HPE published an advisory that discusses two vulnerabilities in their ProLiant BL/DL/ML Servers.

HPE Advisory #7 - HPE published an advisory that discusses an improper input validation vulnerability in their Apollo Servers.

HPE Advisory #8 - HPE published an advisory that discusses an improper input validation vulnerability in their StoreEasy Servers.

 

For more details about these advisories, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-b51 - subscription required.

 
/* Use this with templates/template-twocol.html */