Showing posts with label Genetec. Show all posts
Showing posts with label Genetec. Show all posts

Monday, June 22, 2026

Review - Public ICS Disclosures – Week of 6-13-26 – Part 3

For Part 3 we have 10 vendor updates from CODESYS (4), D-Link (2), FortiGuard, HP, Moxa (2). There are two researcher reports for vulnerabilities in products from Phoenix Contact and Sprecher Automation. Finally, we have two exploits for products from D-Link and Genetec. 

Updates  

CODESYS Update #1 - CODESYS published an update for their Auditlog advisory that was originally published on March 24th, 2026. 

CODESYS Update #2 - CODESYS published an update for their Control advisory that was originally published on May 21st, 2026, and most recently updated on May 26th, 2026. 

CODESYS Update #3 - CODESYS published an update for their Control advisory that was originally published on May 21st, 2026, and most recently updated on May 26th, 2026. 

CODESYS Updte #4 - CODESYS published an update for their Control V3 advisory that was originally puublished on March 24th, 2026. 

D-Link Advisory #1 - D-Link published an update for their DWR-921 advisory that was originally published on April 22nd, 2021.  

D-Link Advisory #2 - D-Link published an update for their DCS-935L advisory that was originally published on September 12th, 2025. 

FortiGuard Update - FortiGuard published an update for their FortiOS advisory that was originally published on June 10th, 2025. 

HP Update - HP published an update for their Intel Chipset advisory that was originally published on October 17th, 2025, and most recently updated on March 19th, 2026. 

Moxa Update #1 - Moxa published an update for their Linux Kernel advisory that was originally published on May 26th, 2026. 

Moxa Update #2 - Moxa published an update for their NPort 5000 Series advisory that was originally published on October 3rd, 2023, and most recently updated on October 23rd, 2023. 

Researcher Reports  

Phoenix Contact Report - Nozomi Networks published a report that describes six vulnerabilities in the Phoenix Contact PLCnext product. 

Sprecher Report - SEC Consult published a report that describes seven vulnerabilities in the Sprecher SPRECON-E-C/-E-P/-E-T3 systems. 

Exploits  

D-Link Exploit - Indoushka published an exploit for a privlege escalation vulnerability in the D-Link DSL2600U routers. 

Genetec Exploit - Indoushka published an exploit for for an incorrect permission assignement for criitical resource vulnerability in the Genetec RabbitMQ. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-ce6 - subscription required. 

Saturday, June 20, 2026

Review – Public ICS Disclosures – 6-13-26 – Part 1

This is a moderately busy disclosure week.  For Part 1 we have 11 vendor disclosures from Arista, Belden, Dell (2), Dassault, Genetec, HP (2), HPE (2), and iba. 

Advisories  

Arista Advisory - Arista published an advisory that discusses the AirSnitch attacks. 

Belden Advisory - Belden published an advisory that describes a download of code without integrity check vulnerability in their Hirschmann Rail Data Diode. 

Dell Advisory #1 - Dell published an advisory that discusses three vulnerabilities in their Wyse Management Suite. 

Dell Advisory #2 - Dell published an advisory that describes two vulnerabilities in their Wyse Management Suite. 

Dassault Advisory - Dassault published an advisory that describes a path traversal vulnerability in their SOLIDWORKS Visualize product. 

NOTE: Dassault only provides access to advisories to registered owners. 

Genetec Advisory - Genetec published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Security Center systems main server installations. 

HP Advisory #1 - HP published an advisory that discusses an insufficient granularity of access control vulnerability in their business notebook and desktop PCs. 

HP Advisory #2 - HP published an advisory that discusses three vulnerabilities in their One Agent Software Bundled with HP Privacy Settings. 

HPE Advisory #1 - HPE published an advisory that discusses an improper initialization vulnerability in their SimpliVity Servers. 

HPE Advisory #2 - HPE published an advisory that discusses an improper access control for register interface vulnerability in their SimpliVity AMD Servers. 

Iba Advisory - CERT-VDE published an advisory that describes a deserialization of untrusted data vulnerabilities in the iba ibaDatCoordinator and ibaPDA products. 


For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-6-13-26-part - subscription required. 

 
/* Use this with templates/template-twocol.html */