Showing posts with label Frauscher. Show all posts
Showing posts with label Frauscher. Show all posts

Saturday, July 12, 2025

Review – Public ICS Disclosures – Week of 7-5-25 – Part 1

This is a heavy week (even for the monthly cyber disclosure week) for public ICS disclosures, I count over 90 separate disclosures. To make this a reasonable series of reports, I am going to try a new short cut; where a vendor has more than 10 separate disclosures, I am going to list them in a “bulk disclosure” listing.

Bulk Disclosures

Broadcom published 15 separate advisories (including 2 updated advisories) for their Brocade products.

HPE published 21 separate advisories (including 1 updated advisory).

Schneider published 10 separate advisories (including 6 updated advisories).

Siemens published 20 separate advisories (including 17 updated advisories) that were not covered earlier this week by CISA.

Splunk published 12 separate advisories.

Normal Disclosures

Additionally, this week we have vendor disclosures from FortiGuard (5), Frauscher, HMS, and HP (2).

Advisories

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an SQL injection vulnerability in multiple FortiGuard products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improperly implemented security check for standard vulnerability in multiple FortiGuard products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a heap-based buffer overflow vulnerability in their FortiOS product.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes a missing critical step in authentication vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes an insufficient session expiration vulnerability in their FortiIsolator and FortiSandbox products.

Frauscher Advisory - CERT-VDE published an advisory that describes two OS command injection vulnerabilities in the Frauscher FDS products.

HMS Advisory - HMS published an advisory that announces that new firmware versions are available for multiple HMS products that conform to the new cybersecurity requirements found in the Radio Equipment Directive 2025.

HP Advisory #1 - HP published an advisory that discusses two transient execution vulnerabilities in multiple HP products.

HP Advisory #2 - HP published an advisory that describes an improper privilege management vulnerability in their Support Assistant product.

 

For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-9c5 - subscription required.

Saturday, December 16, 2023

Review – Public ICS Disclosures – Week of 12-9-23 – Part 1 –

This week we have 22 vendor disclosures from ABB, Beckhoff, BD (2), Bosch (2), Cisco, FortiGuard (3), Frauscher, HPE (3), JTEKT, and Palo Alto Networks (7).

Advisories

ABB Advisory - ABB published an advisory that discusses the Apache ActiveMQ deserialization of untrusted data vulnerability that is listed on the CISA Known Exploited Vulnerabilities Catalog.

Beckhoff Advisory – CERT-VDE published an advisory that describes an open redirect vulnerability in the Beckhoff TwinCAT/BSD product.

BD Advisory #1 - BD published an advisory that discusses the Windows 7 Operating System End of Life Notice.

BD Advisory #2 - BD published an advisory that discusses an out-of-bounds write vulnerability that is listed in the CISA KEV catalog.

Bosch Advisory #1 - Bosch published an advisory that describes two improper handling of a malformed API request vulnerabilities in their BT software products

Bosch Advisory #2 - Bosch published an advisory that describes a command injection vulnerability in their Bosch IP Cameras.

Cisco Advisory - Cisco published an advisory that discusses the recent Apache Struts vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes a use of externally controlled format string vulnerability in their FortiOS, FortiProxy and FortiPAM products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a double free vulnerability in their FortiOS and FortiPAM HTTPSd daemon.

Frauscher Advisory - CERT-VDE published an advisory that describes a code injection vulnerability in the Frauscher FDS102 for FAdC/FAdCi.

HPE Advisory #1 - HPE published an advisory that discusses seven vulnerabilities in their Cray Programming Environment.

HPE Advisory #2 - HPE published an advisory that discusses six vulnerabilities in their Intelligent Management Center (iMC) product.

HPE Advisory #3 - HPE published an advisory that discusses 14 vulnerabilities in their Virtualized Telecommunication Management Information Platform (vTeMIP) application.

JTEKT Advisory - JTEKT published an advisory that describes four uncontrolled resource consumption vulnerabilities in their HMI GC-A2 series products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a weakness introduced during design vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an argument injection vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes an OS command injection vulnerability in their PAS-OS product.

Palo Alto Networks Advisory #6 - Palo Alto Networks published an advisory that describes an improper privilege management vulnerability in their PAN-OS product.

Palo Alto Networks Adviosry #7 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS product.

 

For more details about these disclosures, including links to 3rd party advisories, vendor advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-9fa https://tinyurl.com/yty8yuyt- subscription required. 

Saturday, September 23, 2023

Review – Public ICS Disclosures – Week of 9-16-23

This week we have 15 vendor disclosures from Fauscher, GE Gas Power, HPE (4), Ingeteam, Mitsubishi, Phoenix Contact, QNAP (3), Schweitzer Engineering Labs (2), and Zyxel. There are five vendor updates for products from Broadcom (2) and Palo Alto Networks (3). There are also two researcher reports for products from Atos and Royal Aps. Finally, we have an exploit for products from Ivanti.

Advisories

Frauscher Advisory – CERT-VDE published an advisory that describes three vulnerabilities in their FDS101 for FAdC/FAdCi product.

GE Advisory - GE published an advisory that discusses seven vulnerabilities in the Nozomi Guardian/CMC.

HPE Advisory #1 - HPE published an advisory that discusses two vulnerabilities in their NonStop Products.

HPE Advisory #2 - HPE published an advisory that describes four incomplete cleanup vulnerabilities in their NonStop Products.

HPE Advisory #3 - HPE published an advisory that discusses two improper initialization vulnerabilities in their ProLiant AMD XL Servers.

HPE Advisory #4 - HPE published an advisory that discusses two improper initialization vulnerabilities in their ProLiant AMD DL Servers.

Ingeteam Advisory - Incibe-CERT published an advisory that describes three input validation vulnerabilities in the Ingeteam INGEPAC DA3451 and INGEPAC FC5066.

Mitsubishi Advisory - Mitsubishi published an advisory that describes an incorrect default permissions vulnerability in their FA Engineering Software products.

QNAP Advisory #1 - QNAP published an advisory that describes a classic buffer overflow vulnerability in their Multimedia Console products.

QNAP Advisory #2 - QNAP published an advisory that describes a classic buffer overflow vulnerability in their legacy versions of QTS products.

QNAP Advisory #3 - QNAP published an advisory that discusses three vulnerabilities in their QTS, QuTS hero, and QuTScloud.

SEL Advisory #1 - SEL published an advisory that reports vulnerabilities in their Protocol Services.

SEL Advisory #2 - SEL published an advisory that reports vulnerabilities in their Blueframe OS.

Zyxel Advisory - Zyxel published an advisory that discusses the report of a 2017 vulnerability in their EMG2926-Q10A product being listed on  CISA Known Exploited Vulnerabilities (KEV) catalog.

Updates

Broadcom Update #1 - Broadcom published an update for their Apache HTTP Server advisory that was originally published on August 1st, 2023.

Broadcom Update #2 - Broadcom published an update for their HTTP Server advisory that was originally published on August 1st, 2023.

Palo Alto Networks Update #1 - Palo Alto Networks published an update for their TunnelCrack vulnerabilities advisory that was originally published on August 16th, 2023 and most recently updated on August 21st.

Palo Alto Networks Update #2 - Palo Alto Networks published an update for their Cortex XDR Agent advisory that was published on September 9th.

Palo Alto Networks Update #3 - Palo Alto Networks published an update for their BGP Software advisory that was published on September 13th, 2023.

Reports

Atos Report - SEC Consult published a report describing two vulnerabilities in the Atos Unify OpenScape. The report includes proof-of-concept code.

Royal Aps Report - Zero Science published a report that describes a heap memory corruption vulnerability in the Royal Apps RoyalTSX remote access tool.

Exploit

Ivanti Exploit - Ege Balci published a Metasploit module for an out-of-bounds write vulnerability in the Ivanti Avalanche MDM.

 

For more details about these disclosures, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-53a - subscription required.

Saturday, July 8, 2023

Review – Public ICS Disclosures – Week of 7-1-23

This week we have eleven vendor disclosures from Aruba Networks, Bosch (2), Enphase, Frauscher Sensortechnik, Hikvision, Moxa, Softing (2), VMware and Zyxel. And we have 29 researcher reports for products from Panasonic (3), Milesight (25), and Siemens.

Advisories

Aruba Advisory - Aruba published an advisory that describes nine vulnerabilities in the Aruba OS products.

Bosch Advisory #1 - Bosch published an advisory that discusses two vulnerabilities in their FL MGUARD family devices.

Bosch Advisory #2 - Bosch published an advisory that discusses a missing authentication for critical function vulnerability in their SLC-0-GPNT00300 interface module.

Enphase Advisory - Enphase published an advisory that describes an OS command injection vulnerability in their Enphase IQ Gateway (Envoy).

Frauscher Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1.

Hikvision Advisory - Hikvision published an advisory that describes two vulnerabilities in their access control/intercom products.

Moxa Advisory - Moxa published an advisory that describes an observable response discrepancy vulnerability in their TN-5900 Series product.

Softing Advisory #1 - Softing published an advisory that describes two vulnerabilities in their OPC UA C++ SDK and Secure Integration Server.

Softing Advisory #2 - Softing published an advisory that describes an uncontrolled resource consumption vulnerability in a number of their products.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their SD-WAN (Edge) product.

Zyxel Advisory - Zyxel published an advisory that describes a classic buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Researcher Reports

Panasonic Reports - AWESEC published three reports describing individual vulnerabilities in the Panasonic Panasonic AiSEG2.

Milesight Reports - Talos Intelligence published 25 reports (some with multiple vulnerabilities) for the Milesight UR32L urvpn_client and MilesightVPN server.

Siemens Report - SEC Consult published a report describing the four vulnerabilities in the Siemens A8000 product.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-bcb - subscription required.

 
/* Use this with templates/template-twocol.html */