Showing posts with label Gerbv. Show all posts
Showing posts with label Gerbv. Show all posts

Saturday, March 5, 2022

Review - Public ICS Disclosures – Week of 2-26-22

This week we have twelve vendor disclosures from ABB, Beckhoff, Broadcom (2), B&R Automation, Delta Industrial Automation, Gerbv, OMRON, PcVue Solutions, Tanzu (2), and VMware. We also have two end-of-life notices from We have one researcher report for products from Swift Sensors. Finally, we have four exploits reported for products from WAGO, Hikvision, Axis, and the PwnKit vulnerability.

ABB Advisory - ABB published an advisory describing a denial of service vulnerability in their AC 800M MMS.

Beckhoff Advisory - Beckhoff published an advisory discussing a NULL pointer dereference vulnerability in their products with OPC UA technology.

NOTE: This vulnerability may be found in other vendor products utilizing OPC UA technology.

Broadcom Advisory #1 - Broadcom published an advisory discussing the LOGBACK-1591 vulnerability in their Brocade Fibre Channel Products.

Broadcom Advisory #2 - Broadcom published an advisory discussing the Log4Shell vulnerabilities.

B&R Advisory - B&R published an advisory discussing a deserialization of untrusted data vulnerability in their B&R APROL product line.

NOTE: This vulnerability may affect other vendor products that use Apache Chainsaw.

Delta Advisory - Incibe CERT published an advisory describing four vulnerabilities in the Delta CNCSoft ScreenEditor, and DIAEnergie products.

Gerbv Advisory - Incibe CERT published an advisory discussing seven vulnerabilities in the Gerbv file view.

Omron Advisory - JP CERT published an advisory describing five vulnerabilities in the OMRON CX-Programmer.

PcVue Advisory - PcVue published a notice discussing four vulnerabilities in their Dream Report products.

Tanzu Advisory #1 - Tanzu published an advisory describing an improper privilege management vulnerability in their Spring Cloud Gateway.

Tanzu Advisory #2 - Tanzu published an advisory describing a code injection vulnerability in their Spring Cloud Gateway.

VMware Advisory - VMware published an advisory describing an uncontrolled search path vulnerability in their VMware Tools for Windows.

Swift Sensor Report - Cisco Talos published a report describing an authentication bypass vulnerability in the Swift Sensor Gateway.

Braun End-of-Life Notices - Braun USA published end-of-life notices for their Dialog+ Version 8 and Dia70 Portable RO products.

WAGO Exploit - Momen Eldawakhly published an exploit for a privilege escalation vulnerability in the WAGO 750-8212 PFC200 G2 2ETH RS.

Hikvision Exploit - Bashis published a Metasploit module for a command injection vulnerability in unspecified Hikvision IP Camera.

Axis Exploit - Jbaines-r7 published a Metasploit module for an unrestricted upload of applications ‘feature’ in unspecified Axis IP cameras.

PwnKit Exploit - Qualys Security published a Metasploit module for the PwnKit vulnerability.

 

For more details about these disclosures, including links to third-party reports, researcher reports and exploits, see my article at CFSN Detailed Analysis - - subscription required.

Sunday, February 6, 2022

Review - Public ICS Disclosures – Week of 1-29-22 – Part 2

For Part 2 we have four more vendor disclosures from QNAP, TI, VMware, and Fujitsu. We also have five updates from Boston Scientific, Dell, Hillrom, Johnson Controls, and QNAP. There are also 98 researcher reports for vulnerabilities in products from Gerbv (2), and Bentley (96). Finally, we have three exploit reports for products from Moxa (2), and WAGO.

QNAP Advisory - QNAP published an advisory discussing the Deadbolt Ransomware attacks.

TI Advisory - TI published an advisory discussing physical security attacks on ‘silicon devices.’

VMware Advisory - VMware published an advisory describing an information disclosure vulnerability in their VMware Cloud Foundation.

Fujitsu Advisory - Fujitsu published an advisory discussing 15 vulnerabilities in Insyde® Firmware.

Boston Scientific Update - Boston Scientific published an update for their Log4Shell  advisory.

Dell Update - Dell published an update for their generic Log4Shell advisory.

Hillrom Update - Hillrom published an update for their Log4Shell advisory.

Johnson Controls Update - Johnson Controls published an update for their Log4Shell advisory.

QNAP Update - QNAP published an update for their QTS and QuTS hero advisory that was originally published on January 13th, 2021 and most recently updated on January 25th, 2022.

Gerbv Reports - Talos published two reports of vulnerabilities in the Gerbv RS-274X viewer.

Bentley Reports - The Zero Day Initiative published 96 reports (ZDI-22-149 thru ZDI-22-243ZDI) about vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Moxa Exploit #1 - Matthew Bergin published an exploit for a firmware upgrade vulnerability in the Moxa TN-5900.  

Moxa Exploit #2 - Matthew Bergin published an exploit for a command injection vulnerability vulnerability in the Moxa TN-5900.  

WAGO Exploit - Gerhard Hechenberger published an exploit for an improper handling of exceptional conditions vulnerability in the WAGO 750-8xxx PLC.

NOTE: This was reported as a third-party (CODESYS) vulnerability, so this exploit may work (with or without modification?) on other vendor products.

 

For more details on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-d73 - subscription required.

Saturday, December 11, 2021

Review - Public ICS Disclosures – Week of 12-4-21

It is early yet, but we do have two vendor disclosures for the log4shell vulnerability from SonicWall and VMware. We also have nine routine vendor disclosures from ABB, Bosch, Helmholz (2), QNAP (4), and SonicWall. Finally, there are two researcher reports of vulnerabilities in products from Gerbv.

Log4Shell Advisory #1 - SonicWall published an advisory discussing the log4shell vulnerability.

Log4Shell Advisory #2 - VMware published an advisory discussing the log4shell vulnerability.

ABB Advisory - ABB published an advisory describing a missing authentication vulnerability in their RobotWare.

Bosch Advisory - Bosch published an advisory describing four vulnerabilities in their BT software products.

Helmholz Advisory #1 - CERT-VDE published an advisory describing two vulnerabilities in the Helmholz shDialup program.

Helmholz Advisory #2 - CERT-VDE published an advisory describing a response discrepancy information disclosure vulnerability in the Helmholz myREX24 and myREX24-virtual software.

QNAP Advisory #1 - QNAP published an advisory describing an improper authentication vulnerability in their Qfile for Android application.

QNAP Advisory #2 - QNAP published an advisory describing a reflected cross-site scripting vulnerability in their QNAP NAS running Kazoo Server.

QNAP Advisory #3 - QNAP published an advisory describing a stack-based buffer overflow vulnerability in their QNAP NAS running Surveillance Station.

QNAP Advisory #4 - QNAP published an advisory discussing reports that a bitcoin miner has been reported to target QNAP NAS.

SonicWall Advisory - SonicWall published an advisory describing eight vulnerabilities in their SMA 100 series appliances.

Gerbv Report #1 - Talos published a report describing an out-of-bounds write vulnerability in the Gerbv RS-274X aperture macro.

Gerbv Report #2 - Talos published a report describing an integer overflow or wraparound vulnerability in the Gerbv RS-274X aperture macro.

For more details on these advisories and reports, including links to 3rd party advisories and supporting research reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12 - subscription required.

Saturday, November 6, 2021

Review - Public ICS Disclosure – Week of 10-30-21

This week we have 14 vendor disclosures from Beckhoff, Boston Scientific, Hitachi, Hitachi Energy (7), HPE, Philips, Phoenix Contacts, and Tanzu. There is also a researcher report about vulnerabilities in products from Gerbv. Finally, there is an exploit for products from Sonicwall.

Beckhoff Advisory - Beckhoff published an advisory describing a relative path traversal vulnerability in their TwinCAT OPC UA Server.

Boston Scientific Advisory - Boston Scientific published an advisory discussing the PrintNightmare vulnerabilities.

Hitachi Advisory - Hitachi published an advisory discussing 35 vulnerabilities in their Hitachi Disk Array Systems.

Hitachi Energy Advisory #1 - Hitachi published an advisory discussing 36 vulnerabilities in their Transformer Asset Performance Management (APM) Edge products.

Hitachi Energy Advisory #2 - Hitachi published an advisory describing an insufficient security control vulnerability in their Relion® 670/650/SAM600-IO series Products.

Hitachi Energy Advisory #3 - Hitachi published an advisory describing an insufficient security control in their GMS600 generator circuit breakers.

Hitachi Energy Advisory #4 - Hitachi published an advisory describing an insufficient security control vulnerability in their PWC600 controllers.

Hitachi Energy Advisory #5 - Hitachi published an advisory describing an insecure boot image vulnerability in their Relion® 670/650/SAM600-IO series Products.

Hitachi Energy Advisory #6 - Hitachi published an advisory describing an authentication bypass vulnerability in their Counterparty Settlement and Billing (CSB) Product.

Hitachi Energy Advisory #7 - Hitachi published an advisory describing an authentication bypass vulnerability in their Retail Operations Product.

HPE Advisory - HPE published an advisory discussing five vulnerabilities in their Edgeline EL300 Converged Edge Systems.

Philips Advisory - Philips published an advisory discussing the Cisco input validation vulnerability.

Phoenix Contacts Advisory - Phoenix Contacts published an advisory describing a ‘zip-slip’ vulnerability in their Automation Worx Software Suite.

Tanzu Advisory - Tanzu published an advisory discussing a missing release of memory after effective lifetime vulnerability in their Spring Cloud Gateway.

Gerbv Report - Talos published a report about an out-of-bounds write vulnerability in the in the drill format T-code tool number functionality of Gerbv 2.7.0.

Sonicwall Exploit - Vulnerability Labs published an exploit for a cross-site scripting vulnerability in the Sonicwall SonicOS.

For more details about these advisories, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10 - subscription required.

 
/* Use this with templates/template-twocol.html */