Showing posts with label GE Grid Solutions. Show all posts
Showing posts with label GE Grid Solutions. Show all posts

Saturday, November 11, 2023

Review – Public ICS Disclosures – Week of 11-4-23 – Part 1

This week we have 23 vendor disclosures from Broadcom (15), Fuji Electric, GE Gas Power, GE Grid Solutions (4), and Hitachi (2).

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses an unquoted search path or element vulnerability in their Fabric OS.

Broadcom Advisory #2 - Broadcom published an advisory that describes a missing HTTP headers vulnerability in their Brocade ASCG products.

Broadcom Advisory #3 - Broadcom published an advisory that discusses a use after free vulnerability in their Fabric OS products.

Broadcom Advisory #4 - Broadcom published an advisory that discusses a missing authentication for critical function vulnerability in their Brocade ASG.

Broadcom Advisory #5 - Broadcom published an advisory that discusses an arbitrary code execution vulnerability in their Brocade ASCG OVA.

Broadcom Advisory #6 - Broadcom published an advisory that discusses an out-of-bounds write vulnerability in their Brocade ASGC product.

Broadcom Advisory #7 - Broadcom published an advisory that discusses an infinite loop vulnerability in their Brocade ASCG OVA product.

Broadcom Advisory #8 - Broadcom published an advisory that describes in improper input validation vulnerability in their Brocade Active Support Connectivity Gateway (ASC-G).

Broadcom Advisory #9 - Broadcom published an advisory that discusses an infinite loop vulnerability in their Brocade ASCG OVA product.

Broadcom Advisory #10 - Broadcom published an advisory that discusses four vulnerabilities in their Brocade ASCG product.

Broadcom Advisory #11 - Broadcom published an advisory that discusses an improper verification of cryptographic signature in their Brocade ASCG product.

Broadcom Advisory #12 - Broadcom published an advisory that discusses an OS command injection vulnerability in their Fabric OS product.

Broadcom Advisory #13 - Broadcom published an advisory that discusses a NULL pointer dereference vulnerability in their Brocade SANnav product.

Broadcom Advisory #14 - Broadcom published an advisory that discusses an improper input validation vulnerability in their Brocade ASCG.

Broadcom Advisory #15 - Broadcom published an advisory that discusses an integer overflow or wraparound vulnerability in their Brocade ASCG OVA product.

Fuji Advisory - JP-CERT published an advisory that describes seven vulnerabilities in the Fuji Electric TELLUS and V-Server products.

GE Gas Power Advisory - GE Gas Power published an advisory that discusses the web UI feature in Cisco IOS XE vulnerabilities.

GE Grid Solutions Advisories - GE Grid Solutions published 4 advisories for vulnerabilities in their D20MX Substation Controller, D400 Advanced Substation Gateway, G100 Advanced Substation Gateway, and G500 Advanced Substation Gateway products.

Hitachi Advisory #1 - Hitachi published an advisory that discusses 74 vulnerabilities in their Disc Array products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses three Unauthorized update vulnerabilities in multiple Hitachi products.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-517 - subscription required.

Saturday, October 22, 2022

Review – Public ICS Disclosures – Week of 10-15-22

This week we have fourteen vendor disclosures from Bosch (2), Broadcom, GE Grid Solutions, HP, Meinberg, Milestone, Siemens, SonicWall, Tanzu, TRUMPF, WAGO (2), and Yokogawa Test and Measurement. We also have a vendor update from HPE. Finally, we have an exploit for products from Tanzu.

Bosch Advisory #1 - Bosch published an advisory that discusses an improper validation of integrity check value vulnerability in their Bosch DSA E2800 products.

Bosch Advisory #2 - Bosch published an advisory that describes two cross-site scripting vulnerabilities in their VIDEOJET multi 4000.

Broadcom Advisory - Broadcom published an advisory that discusses the Text4Shell vulnerability.

GE Grid Solutions Advisory - GE Grid Solutions published an advisory that describes vulnerabilities in their MS 3000 Transformers monitoring system.

HP Advisory - HP published an advisory that discusses a PCR measurement vulnerability in multiple HP products.

Meinberg Advisory - Meinberg published an advisory that discusses two vulnerabilities (both with publicly available exploits) in their LANTIME firmware.

Milestone Advisory - Milestone published an advisory that discusses an authentication bypass vulnerability in their Mobile Server.

Siemens Advisory - Siemens published an advisory that describes an authentication bypass vulnerability in their Siveillance Video Mobile Server.

SonicWall Advisory - SonicWall published an advisory that discusses the Text4Shell vulnerability.

Tanzu Advisory #1 - Tanzu published an advisory that describes an HTTP request forgery vulnerability in their Spring Data REST.

Tanzu Advisory #2 - Tanzu published an advisory that describes an information disclosure vulnerability in their Reactor Netty HTTP Server.

TRUMPF Advisory - CERT-VDE published an advisory that describes an improper access control vulnerability in multiple TRUMPF products.

WAGO Advisory #1 - CERT-VDE published an advisory that discusses fourteen vulnerabilities in the WAGO 750 series controllers and WAGO-I/O-PRO.

WAGO Advisory #2 - CERT-VDE published an advisory that describes an expected behavior violation vulnerability in multiple WAGO products.

Yokogawa Advisory - Yokogawa Test and Measurement published an advisory that describes a buffer overflow vulnerability in their WTViewerE.

HPE Update - HPE published an update for their ProLiant Servers advisory that was originally published on May 18th, 2022.

Tanzu Exploit - Ayan Saha published a Metasploit module for a code injection vulnerability in the Tanzu Spring Cloud Gateway.

 

For more details on these disclosures, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-1b0 - subscription required.


 
/* Use this with templates/template-twocol.html */