Showing posts with label HMS. Show all posts
Showing posts with label HMS. Show all posts

Saturday, March 14, 2026

Review – Public ICS Disclosures – Week of 3-7-26 – Part 1

This is a busy cyber disclosure week. For Part 1 we have bulk vendor disclosures from FortiGuard (11), and Splunk (13). There are 15 additional vendor disclosures from ABB (2), CODESYS, Eaton, GE Vernova, Hitachi, HMS (2), HP (3), and HPE (4).

Advisories

Bulk Vendor Disclosures – FortiGuard

Authentication Lockout Bypass via Race Condition,

Buffer Overflow in LLDP OUI field,  

Buffer overflow via fgtupdates service,  

Format string vulnerability in fazsvcd,

Lack of TLS Certificate Validation during initial SSO Authentication,

MFA Bypass in GUI,

OS command injection on vmimages update feature,

Privilege escalation using undocumented CLI command,

SQL injection in jsonrpc api,

XSS in LDAP server option, and

Shell command limitation bypass by SSH local config overriding.

Bulk Vendor Disclosures – Splunk

Third-Party Package Updates in Splunk AppDynamics Analytics Agent - March 2026,

Third-Party Package Updates in Splunk AppDynamics Database Agent - March 2026,

Third-Party Package Updates in Splunk AppDynamics NodeJS Agent - March 2026,

Third-Party Package Updates in Splunk AppDynamics Java Agent - March 2026,

Third-Party Package Updates in Splunk AppDynamics Private Synthetic Agent - March 2026,

Third-Party Package Updates in Splunk AppDynamics Machine Agent - March 2026,

Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - March 2026,

Third-Party Package Updates in Splunk Enterprise - March 2026,

Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk Enterprise,

Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise,

Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise,

Remote Command Execution (RCE) through the '/splunkd/upload/indexing/preview' REST endpoint in Splunk Enterprise, and

Stored Cross-Site Scripting (XSS) through Path Traversal in Splunk Enterprise.

ABB Advisory #1 - ABB published an advisory that describes three vulnerabilities in their AWIN Gateways products.

ABB Advisory #2 - ABB published an advisory that discusses an out-of-bounds write vulnerability in their AC500 V3 product.

CODESYS Advisory - CODESYS published an advisory that describes a TOCTOU race condition vulnerability in their Installer product.

Eaton Advisory - Eaton published an advisory that describes a storing passwords in a recoverable format vulnerability in their EasySoft product.

GE Vernova Advisory - GE published a security statement on the US-Iran conflict.

Hitachi Advisory - Hitachi published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their Command Suite product.

HMS Advisory #1 - HMS published an advisory that describes four vulnerabilities in their Ewon Flexy and Ewon Cosy+ gateways.

HMS Advisory #2 - HMS published an advisory that addresses HMS compliance with the EU Radio Equipment Directive 3.3.

HP Advisory #1 - HP published an advisory that discusses six vulnerabilities in multiple HP product lines.

HP Advisory #2 - HP published an advisory that discusses 43 vulnerabilities in their Device Manager product.

HP Advisory #3 - HP published an advisory that discusses two vulnerabilities in multiple HP product lines.

HPE Advisory #1 - HPE published an advisory that discusses an improper handling of values vulnerability in their Compute Scale-up Server 3200 Platform.

HPE Advisory #2 - HPE published an advisory that discusses eight vulnerabilities in multiple server products.

HPE Advisory #3 - HPE published an advisory that discusses a code injection vulnerability in their Telco Intelligent Assurance product.

HPE Advisory #4 - HPE published an advisory that describes five vulnerabilities in their Aruba Networking AOS-CX product.

 

For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-982 - subscription required.

Saturday, July 12, 2025

Review – Public ICS Disclosures – Week of 7-5-25 – Part 1

This is a heavy week (even for the monthly cyber disclosure week) for public ICS disclosures, I count over 90 separate disclosures. To make this a reasonable series of reports, I am going to try a new short cut; where a vendor has more than 10 separate disclosures, I am going to list them in a “bulk disclosure” listing.

Bulk Disclosures

Broadcom published 15 separate advisories (including 2 updated advisories) for their Brocade products.

HPE published 21 separate advisories (including 1 updated advisory).

Schneider published 10 separate advisories (including 6 updated advisories).

Siemens published 20 separate advisories (including 17 updated advisories) that were not covered earlier this week by CISA.

Splunk published 12 separate advisories.

Normal Disclosures

Additionally, this week we have vendor disclosures from FortiGuard (5), Frauscher, HMS, and HP (2).

Advisories

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an SQL injection vulnerability in multiple FortiGuard products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improperly implemented security check for standard vulnerability in multiple FortiGuard products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a heap-based buffer overflow vulnerability in their FortiOS product.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes a missing critical step in authentication vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes an insufficient session expiration vulnerability in their FortiIsolator and FortiSandbox products.

Frauscher Advisory - CERT-VDE published an advisory that describes two OS command injection vulnerabilities in the Frauscher FDS products.

HMS Advisory - HMS published an advisory that announces that new firmware versions are available for multiple HMS products that conform to the new cybersecurity requirements found in the Radio Equipment Directive 2025.

HP Advisory #1 - HP published an advisory that discusses two transient execution vulnerabilities in multiple HP products.

HP Advisory #2 - HP published an advisory that describes an improper privilege management vulnerability in their Support Assistant product.

 

For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-9c5 - subscription required.

Monday, April 14, 2025

Review – Public ICS Disclosures – Week of 4-5-25 – Part 3

For Part 3 we have 23 vendor updates from Dell, FortiGuard, HP, Schneider (4), and Siemens (16). There are five researcher reports for vulnerabilities in products from MedDream. Finally, we have two exploits for products from HMS and Palo Alto Networks.

Updates

Dell Update - Dell published an update for their ThinOS advisory that was originally published on March 4th, 2025, and most recently updated on March 18th, 2025.

FortiGuard Update - FortiGuard published an update for their ipsec ike advisory that was originally published on January 14th, 2025.

HP Update - HP published an update for their PC BIOS advisory that was originally published on October 24th, 2024.

Schneider Update #1 - Schneider published an update for their Modicon M580 PLCs advisory that was originally published on January 14th, 2025.

Schneider Update #2 - Schneider published an update for their VxWorks DHCP server advisory that was originally published on January 14th, 2025.

Schneider Update #3 - Schneider published an update for their Modicon Controllers M340 advisory that was originally published on November 12th, 2024.

Schneider Update #4 - Schneider published an update for their BadAlloc Vulnerabilities advisory that was originally published on November 9th, 2021, and most recently updated on January 14th, 2025.

Siemens Update #1 - Siemens published an update for their FTP Server of Nucleus RTOS advisory that was originally published on October 11th, 2022, and most recently updated on May 14th, 2024.

Siemens Update #2 - Siemens published an update for their Frame Aggregation advisory that was originally published on July 13th, 2021, and most recently updated on April 12th, 2022.

Siemens Update #3 - Siemens published an update for their SIMATIC S7-1500 advisory that was originally published on October 8th, 2024, and most recently updated on March 11th, 2025.

Siemens Update #4 - Siemens published an update for their Fortigate NGFW advisory that was originally published on February 11th, 2025, and most recently update on March 11th, 2025. Includes adding a new vulnerability with publicly available exploits.

Siemens Update #5 - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on February 11th, 2025, and most recently updated on March 11th, 2025.

Siemens Update #6 - Siemens published an update for their Fortigate NGFW advisory that was originally published on July 9th, 2024, and most recently updated on February 11th, 2025.

Siemens Update #7 - Siemens published an update for their Siemens Industrial Products advisory that was originally published on February 14th, 2023, and most recently updated on August 13th, 2024.

Siemens Update #8 - Siemens published an update for their SIMATIC S7-1500 TM MFP advisory that was originally published on March 11th, 2025.

Siemens Update #9 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2023, and most recently update on March 11th, 2025.

Siemens Update #10 - Siemens published an update for their SIMATIC IPC DiagBase advisory that was originally published on February 11th, 2025.

Siemens Update #11 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on July 9th, 2024, and most recently updated on December 10th, 2024.

Siemens Update #12 - Siemens published an update for their Palo Alto Networks PAN-OS advisory that was originally published on November 22nd, 2024, and most recently updated on February 19th, 2025.

Siemens Update #13 - Siemens published an update for their Insyde BIOS advisory that was originally published on February 22nd, 2022, and most recently updated on November 14th, 2023.

Siemens Update #14 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on March 9th, 2024, and most recently updated on November 12th, 2024. – Includes adding vulnerability that is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Siemens Update #15 - Siemens published an update for their Webserver of SIMATIC Products advisory that was originally published on February 11th, 2025, and most recently updated on March 11th, 2025.

Siemens Update #16 - Siemens published an update for their Web Server of SIMATIC S7-1500 CPUs advisory that was originally published on October 8th, 2024, and most recently updated on March 11th, 2025.

Researcher Reports

MedDream Reports - ZDI published five reports describing individual vulnerabilities in the MedDream PACS Server. The

Exploits

HMS Exploit - CodeB0ss published an exploit for an OS command injection vulnerability in the HMS Cosy+ devices.

Palo Alto Networks Exploit - ByteHunter published an exploit for a missing authentication for critical function vulnerability in the Palo Alto Networks Expedition product.

 

For more information about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-741 - subscription required.

Thursday, January 23, 2025

Review – 6 Advisories Published – 1-23-25

Today CISA’s NCCIC-ICS published six control system security advisories for products from HMS, Schneider (3), Hitachi Energy, and mySCADA.

Advisories

HMS Advisory - This advisory describes a cleartext transmission of sensitive information vulnerability in the HMS EWON Flexy 202 IIoT data gateway.

Schneider Advisory #1 - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Schneider EcoStruxure Power Build Rapsody.

Schneider Advisory #2 - This advisory describes an improper privilege-management vulnerability in the Schneider Easergy Studio products.

Schneider Advisory #3 - This advisory describes a cleartext storage of sensitive information vulnerability in the Schneider EVlink Home Smart and Schneider Charge charging stations.

Hitachi Energy Advisory - This advisory describes an improperly implemented security check for standard vulnerability in the Hitachi Energy RTU500 series products.

MySCADA Advisory - This advisory describes two OS command injection vulnerabilities in the mySCADA myPRO products.

 

For more information on these vulnerabilities (four of which have been previously reported here), including a down-the-rabbit-hole look at the coordination process, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-published-1-23-25 - subscription required.

Saturday, December 28, 2024

Review – Public ICS Disclosures – Week of 12-21-24

This week we have three vendor disclosures from Hitachi, Palo Alto Networks, and Philips. We also have six researcher reports for vulnerabilities in products from ABB (5) and HMS.

Advisories

Hitachi Advisory - Hitachi published an advisory that discusses 29 vulnerabilities in their Disk Array Systems.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that describes an improper check for unusual or exceptional conditions vulnerability in multiple Palo Alto Networks products.

Philips Advisory - Philips published an advisory that discusses the Apache Struts unrestricted upload of file with dangerous type vulnerability.

Researcher Reports

ABB Reports - Zero Science published five reports about vulnerabilities (all with publicly available exploits) in the ABB Cylon Aspect building energy management product.

HMS Report - CyberDanube published a report that describes a code injection vulnerability (with publicly available exploit) in the HMS Ewon Flexy 205.

 

For more information on these vulnerabilities, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-136 - subscription required.

Thursday, October 17, 2024

Review – 5 Advisories and 2 Updates Published – 10-17-24

Today, CISA’s NCCIC-ICS published five control system security advisories for products from Kieback&Peter, HMS, Mitsubishi Electric, LCDS, and Elvaco. They also published updates for products from goTenna.

Advisories

Kieback&Peter Advisory - This advisory describes three vulnerabilities in the Kieback&Peter DDC4000 series building automation controllers.

HMS Advisory - This advisory describes an insufficiently protected credentials vulnerability in the HMS WON FLEXY 202 industrial modular gateway.

Mitsubishi Advisory - This advisory describes an improper validation of specified quantity in input vulnerability in the Mitsubishi CNC products.

LCDS Advisory - This advisory describes a cross-site scripting vulnerability in the LCDS LAquis SCADA HMI program.

Elvaco Advisory - This advisory describes four vulnerabilities in the Elvaco CMe3100 metering gateway.

Updates

GoTenna Update #1 - This update provides additional information on the Pro ATAK Plugin advisory that was originally published on September 26th, 2024.

GoTenna Update #2 - This update provides additional information on the Pro X and Pro X2 advisory that was originally published on September 26th, 2024.

 

For more information on these advisories see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-bb1 - subscription required.

Saturday, August 3, 2024

Review – Public ICS Disclosures – Week of 8-27-24

This week we have six vendor disclosures for the regreSSHion vulnerability from Cisco, Eaton, Helmholtz, HPE, Moxa, and Red Lion. We have nine additional vendor disclosures from ABB, Broadcom (4), HP, HPE (2), and Western Digital. There are also four vendor updates from Broadcom, Cisco, Hitachi Energy, and HPE. We also have two researcher reports for products from FortiGuard and Pioneer. Finally, we have an exploit for products from mySCADA.

RegreSSHion Advisories

Cisco published an update for their regreSSHion advisory that was originally published on July 2nd, 2024 and most recently updated on July 26th, 2024.

Eaton published an advisory that announces that Eaton is investigating the vulnerability, but notes that for most Eaton products, SSH service is disable by default.

Helmholtz – CERT-VDE published an advisory that provides a list of affected products and fixed versions.

HPE published an update for their regreSSHion advisory that was originally published on July 10th, 2024.

Moxa published an advisory that provides a list of affected and fixed products.

Red Lion Europe – CERT-VDE published an advisory that provides a list of affected products and fixed versions.

Advisories

ABB Advisory - ABB published an advisory that discusses an insufficiently protected credentials vulnerability in their Automation Builder product.

Broadcom Advisory #1 - Broadcom published an advisory that discusses five vulnerabilities (3 with exploits available) in their Brocade Fabric OS.

Broadcom Advisory #2 - Broadcom published an advisory that discusses nine vulnerabilities (2 with exploit code available) in multiple Broadcom products.

Broadcom Advisory #3 - Broadcom published an advisory that describes a command injection vulnerability in their Brocade 6547 (FC5022) embedded switches.

Broadcom Advisory #4 - Broadcom published an advisory that describes a plain-text storage of passwords vulnerability in their Brocade FabricOS.

HMS Advisory - HMS published an advisory that describes six vulnerabilities in their Cosy+ product line.

HP Advisory - HP published an advisory that discusses 214 vulnerabilities in their ThinPro products.

HPE Advisory #1 - HPE published an advisory that discusses 16 vulnerabilities (5 with publicly available exploits) in their Fiber Channel and SAN Switches.

HPE Advisory #2 - HPE published an advisory that discusses four vulnerabilities (one with publicly available exploits) in their Aruba ClearPass Policy Manager product.

Western Digital Advisory - Western Digital published an advisory that describes a code injection vulnerability in their Discovery Desktop App.

Updates

Broadcom Update - Broadcom published an update for their Azul Zulu advisory that was originally published on July 26th, 2024.

Cisco Update - Cisco published an update for their RADIUS Protocol Spoofing advisory that was originally published on July 10th, 2024 and most recently updated on July 29th, 2024.

Hitachi Energy Update - Hitachi Energy published an update for their IED ConnPacks advisory that was originally published on November 15th, 2022 and most recently updated on June 25th, 2024.

HPE Update - HPE published an update for their Telecommunication Management Information Platform advisory that was originally published on December 12th, 2024.

Researcher Reports

FortiGuard Report - IOActive published a report describing a cross-site scripting vulnerability in the FortiGuard SSL VPN web UI.

Pioneer Report - ZDI published three reports of individual vulnerabilities in the Pioneer DMH-WT7600NEX automotive media center.

Exploits

MySCADA Exploit - Michael Heinzl published a Metasploit module for an OS command injection vulnerability in the mySCADA MyPro product.

 

For more details about these disclosures, including links to 3rd party vendors, see my article at CFSN Detailed analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-dae - subscription required.

Saturday, July 20, 2024

Review – Public ICS Disclosures – Week of 7-13-24

This week we have three vendor disclosures on the regreSSHion vulnerability from Bosch, Broadcom, HMS  We have 14 additional vendor disclosures from ABB, Dell, Fujitsu, Hitachi, HP (4), HPE (3), Rockwell (2), and Wireshark. There are also five vendor updates from BD and HPE (4). Finally, we have four researcher reports about vulnerabilities in products from Asus, Synology, and Unitronics (2).

RegreSSHion Advisories

Bosch published an advisory that lists affected products and fixed versions.

Broadcom published an advisory that lists the products that are not affected.

HMS published an advisory that lists the affected products and announces that fixes have been applied.

Advisories

ABB Advisory - ABB published an advisory that describes an unquoted search path or element vulnerability in their Mint Workbench product.

Dell Advisory - Dell published an advisory that lists a large number (nope, I am not counting them all) of 3rd party vulnerabilities in their ThinOS product.

Fujitsu Advisory - JP-CERT published an advisory that describes a path traversal vulnerability in the Fujitsu Network Edgiot GW1500 product.

Hitachi Advisory - Hitachi published an advisory that discusses 42 vulnerabilities in their Disc Array Systems products.

HP Advisory #1 - HP published an advisory that describes a buffer overflow vulnerability in multiple desk top computers.

HP Advisory #2 - HP published an advisory that describes two privilege escalation vulnerabilities in their display control software.

NOTE: The HP Security Bulletins page lists two additional advisories (here and here), but neither page currently opens.

HPE Advisory #1 - HPE published an advisory that describes a remote bypass of a security restriction vulnerability in their 3PAR Service Processor Software.

HPE Advisory #2 - HPE published an advisory that discusses 17 vulnerabilities (one with known exploits) in their Unified OSS Console Assurance Monitoring (UOCAM) product.

HPE Advisory #3 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML/XL, Synergy, Edgeline and Alletra Servers.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their SequenceManager Server.

Advisory #2 - Rockwell published an advisory that describes an improper input validation vulnerability in their 5015 – AENFTXT product.

Wireshark Advisory - Wireshark published an advisory that describes a packet injection vulnerability in their SPRT dissector product.

Updates

BD Update - BD published an update for their Third-Party ESET advisory that was originally published on March 29th, 2024.

HPE Update #1 - HPE published an update for their Intel Thunderbolt Driver advisory that was originally published on May 14th, 2024 and most recently updated on June 17th, 2024.

HPE Update #2 - HPE published an update for their Intel PROSet/Wireless WiFi and Bluetooth advisory that was originally published on May 14th, 2024 and most recently updated on June 17th, 2024.

HPE Update #3 - HPE published an update for their Intel Chipset Device Software advisory that was originally published on June 28th, 2024.

HPE Update #4 - HPE published an update for their Intel 2024.1 IPU - Chipset Software advisory that was originally published on March 13th, 2024 and most recently updated on April 10th, 2024.

Researcher Reports

Asus Report - BugProve published a report describing a stack-based buffer overflow vulnerability in the Asus RT-AC87U router.

Synology Report - Claroty published a report that describes a classic buffer overflow vulnerability in the Synology BC 500 IP camera.

Unitronics Reports - Claroty published two reports about individual vulnerabilities in the Unitronics Vision Plc.

 

For more information about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-3e2 - subscription required.

Saturday, July 13, 2024

Review – Public ICS Disclosures – Week of 7-6-23 – Part 1

This week we have eight vendor disclosures about the Blast-Radius and RegreSSHion vulnerabilities. We have 25 additional vendor disclosures from BD, FortiGuard (3), Hitachi, Moxa, OPC Foundation, Palo Alto Networks (5), Pepperly+Fuchs (2), Philips, Schneider (4), SEL, and VMware (7).

Blast-RADIUS Advisories

Cisco published an advisory that provides a list of products currently under review as being potentially affected.

HPE published an advisory that provides a list of Aruba Networking products affected.

Palo Alto Networks published an advisory that provides a list of affected products and provides work arounds.

WatchGuard published an advisory that provides a list of products that they are investigating with regards to this vulnerability.

RegreSSHion Advisories

Cisco published an update that updated the lists of affected products, unaffected products, and products currently under review.

HMS published an advisory that provides a list of affected products and reports that: “All servers have been updated on 10/07/2024. No further actions are needed.”

Philips published an advisory that reports that none of their products are affected.

Synology published an advisory that reports that none of their products are affected.

Advisories

BD Advisory - BD published an advisory that discusses an improper privilege management vulnerability in multiple BD products.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiExtender authentication component.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an incorrect parsing of numbers with different radices vulnerability in their FortiOS and FortiProxy IP address validation feature.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiOS and FortiProxy's web SSL VPN UI.

Hitachi Advisory - Hitachi published an advisory that discuses 70 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities.

Moxa Advisory - Moxa published an advisory that discusses a use after free vulnerability (that is listed in CISA’s Known Exploited Vulnerabilities Catalog) in multiple Moxa products.

OPC Foundation - The OPC Foundation published an advisory that describes an allocation of resources without limits or throttling vulnerability in their UA-.NETStandard product.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a hard-coded password vulnerability in their Expedition VM product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes an improper input validation vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an improper verification of cryptographic signature vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes a missing authentication for critical function vulnerability in the Network Expedition product.

Pepperl+Fuchs Advisory #1 - CERT-VDE published an advisory that discusses a use after free vulnerability in their Smart-Ex 02 and Smart-Ex 03 products.

Pepperl+Fuchs Advisory #2 - CERT-VDE published an advisory that describes two vulnerabilities in the Pepperl+Fuchs OIT-XXXX products.

Philips Advisory - Philips published an advisory that discusses a TeamViewer vulnerability. Philips reports that none of their products are affected.

Schneider Advisory #1 - Schneider published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their Wiser Home Controller WHC-5918A.

Schneider Advisory #2 - Schneider published an advisory that describes three vulnerabilities in their Foxboro DCS Core Control Services.

Schneider Advisory #3 - Schneider published an advisory that describes a path traversal vulnerability in their EcoStruxure Foxboro SCADA FoxRTU Station.

Schneider Advisory #4 - Schneider published an advisory that describes a cross-site scripting vulnerability in their Modicon Controllers.

SEL Advisory - SEL published a new version notice for their SEL-5052 Server Software that includes descriptions of cybersecurity fixes.

VMware Advisory #1 - Broadcom published an advisory that describes an SQL injection vulnerability in the VMware Aria Automation product.

VMware Advisories #2 thru #7 - Broadcom re-published six VMware advisories in the Broadcom format.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-c55 - subscription required.

Thursday, July 11, 2024

Review – 20 Advisories and 1 Update Published – 7-11-24

Today, CISA’s NCCIC-ICS published 20 control system security advisories for products from Siemens (17), Rockwell Automation (2), and HMS Industrial Networks. They also updated an advisory for products from Mitsubishi.

Advisories

HMS Advisory - This advisory describes a cross-site scripting vulnerability in the HMS Anybus-CompactCom 30 industrial communication interface.

Rockwell Advisory #1 - This advisory describes two improper privilege management vulnerabilities in the Rockwell FactoryTalk System Services and Policy Manager products.

Rockwell Advisory #2 - This advisory describes three improper input validation vulnerabilities in the Rockwell ThinManager ThinServer.

SIMATIC Advisory #1 - This advisory describes a deserialization of untrusted data vulnerability in the Siemens SIMATIC PCS and STEP 7 products.

SIMATIC Advisory #2 - This advisory describes an exposure of private personal information to an unauthorized actor vulnerability in the Siemens PCS 7 and WinCC SIMATIC products.

SIMATIC Advisory #3 - This advisory describes an improperly controlled sequential memory allocation vulnerability in the Siemens SIMATIC and SIMIT products.

SINEMA Advisory #1 - This advisory describes three command injection vulnerabilities in the Siemens SINEMA Remote Connect Client.

SINEMA Advisory #2 - This advisory describes two command injection vulnerabilities in the Siemens SINEMA Remote Connect Server.

SIPROTEC Advisory - This advisory that describes an inadequate encryption strength vulnerability in the Siemens SIPROTEC products.

TIA Portal Advisory #1 - This advisory describes a deserialization of untrusted data vulnerability in the Siemens TIA Portal, SIMATIC, and SIRIUS products.

TIA Portal Advisory #2 - This advisory describes a deserialization of untrusted data vulnerability in the Siemens TIA Portal and SIMATIC STEP 7 products.

RUGGEDCOM Advisory #1 - This advisory discusses the Terrapin-Attack vulnerability in the Siemens RUGGEDCOM APE1808 product.

RUGGEDCOM Advisory #2 - This advisory describes four vulnerabilities in the Siemens RUGGEDCOM products.

RUGGEDCOM Advisory #3 - This advisory discusses four vulnerabilities in the Siemens RUGGEDCOM APE 1808 product.

JT Open Advisory - This advisory describes two vulnerabilities in the Siemens JT Open and PLM XML SDK products.

Mendix Advisory - This advisory describes a use of hard-coded, security relevant constants vulnerability in the Siemens Mendix Encryption product.

SCALANCE Advisory - This advisory discusses the BlastRadius.Fail vulnerability in multiple Siemens product lines.

SIMCENTER Advisory - This advisory describes 15 vulnerabilities in the Siemens Simcenter Femap product.

Teamcenter Advisory - This advisory describes an out-of-bounds read vulnerability in the Siemens Teamcenter Visualization and JT2Go products.

Remote Connect Server Advisory - This advisory describes 13 vulnerabilities in the Siemens SINEMA Remote Connect Server.

Update

Mitsubishi Update - This update provides additional information for the MELSEC iQ-R advisory that was originally published on December 22nd, 2022 and most recently updated on May 30th, 2024.

 

For more information on these advisories, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/20-advisories-and-1-update-published - subscription required.

 

Saturday, May 6, 2023

Review – Public ICS Disclosures – Week of 4-29-23

This week we have 23 vendor disclosures from Broadcom (6), FortiGuard Labs (9), HMS, Honeywell, HP, Insyde (2), OPC Foundation (2), and Philips. We have five researcher reports for vulnerabilities in products from Sante. Finally, we have an exploit report for products from FortiGuard.

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses a cleartext transmission of sensitive information vulnerabilities in multiple Brocade products.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an HTTP request/response smuggling vulnerability in multiple Brocade products.

Broadcom Advisory #3 - Broadcom published an advisory that discusses an allocation of resources without limit or throttling vulnerability in multiple Brocade products.

Broadcom Advisory #4 - Broadcom published an advisory that discusses a data processing error vulnerability in multiple Brocade products.

Broadcom Advisory #5 - Broadcom published an advisory that discusses a deserialization of untrusted data vulnerability in multiple Brocade products.

Broadcom Advisory #6 - Broadcom published an advisory that discusses a deserialization of untrusted data vulnerability in multiple Brocade products.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an out-of-bounds write vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an open redirect vulnerability in their FortiNAC product.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a use of hard-coded credentials vulnerability in their FortiNAC product.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes an insufficiently protected credentials vulnerability in their FortiNAC.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes a weak authentication vulnerability in their FortiNAC product.

FortiGuard Advisory #6 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiNAC product.

FortiGuard Advisory #7 - FortiGuard published an advisory that describes a weak cryptographic algorithm vulnerability in their FortiNAC product.

FortiGuard Advisory #8 - FortiGuard published an advisory that describes a path traversal vulnerability in their FortiADC product.

FortiGuard Advisory #9 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiADC product.

HMS Advisory - HMS published an advisory that discusses an authentication bypass by capture replay vulnerability in their Anybus Wireless Bridge II/Bolt.

Honeywell Advisory - Honeywell published an end-of-life notice for multiple products.

HP Advisory -HP published an advisory that discusses eleven vulnerabilities in multiple HP products.

Insyde Advisory #1 - Insyde published an advisory that describes an out-of-bounds read vulnerability in their InsydeCrPkg.

Insyde Advisory #2 - Insyde published an advisory that describes an inadequate input validation vulnerability in multiple Intel mobile platforms.

OPC Foundation Advisory #1 - The OPC Foundation published an advisory that describes an improperly controlled sequential memory allocation vulnerability in their OPC UA .NET Standard Reference Server.

OPC Foundation Advisory #2 - The OPC Foundation published an advisory that describes a generation of error message that contains sensitive information vulnerability in their OPC UA .NET Standard Reference Server.

Philips Advisory - Philips published an advisory that discusses the Windows WinVerifyTrust Signature Validation Vulnerability.

Researcher Reports

Sante Reports - The Zero Day Initiative published reports for five vulnerabilities in the Sante DICOM Viewer Pro.

Exploits

FortiGuard Exploit - Code16 published an exploit for an unspecified vulnerability in FortiGate-VM64.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-837 - subscription required.

Saturday, April 15, 2023

Review – Public ICS Disclosures – Week of 4-8-23 – Part 1

And once again it is the Saturday after Cyber Tuesday. For Part 1, we have 34 vendor disclosures from B&R, Flexera, Hikvision, HMS, HP, HPE (3), Insyde (8), Meinberg, Palo Alto Networks (3), Phoenix Contact, Sick, Tanzu (9), and Wireshark (3).

NOTE: It has become obvious that FortiGuard has joined the ranks of organizations that report vulnerabilities en-mass on Cyber Tuesday. As such they will join Schneider and Siemens in being reported in a subsequent Part of the weekend’s Public ICS Disclosure.

Advisories

B&R Advisory - B&R published an advisory that discusses three vulnerabilities in their B&R VC4 Visualization product.

Flexera Advisory - Flexera published an advisory that discusses four vulnerabilities in their FlexNet Publisher product.

Hikvision Advisory - Hikvision published an advisory that describes an improper access control vulnerability in their Hybrid SAN/Cluster Storage products.

HMS Advisory - HMS published an advisory that discusses the INFRA:HALT vulnerabilities.

HP Advisory - HP published an advisory that discusses 31 vulnerabilities in their Device Manager product.

HPE Advisory #1 - HPE published an advisory that describes six disclosure of sensitive information vulnerabilities in their OneView product.

HPE Advisory #2 - HPE published an advisory that describes a disclosure of sensitive information vulnerable in their OneView "Migrate Server Hardware" Option.

HPE Advisory #3 - HPE published an advisory that describes two disclosure of sensitive information vulnerabilities in their OneView Global Dashboard.

Insyde Advisory #1 - Insyde published an advisory that describes a memory corruption vulnerability in their FTBS SMI Handler.

Insyde Advisory #2 - Insyde published an advisory that describes an insufficient input validation vulnerability in their ChipsetSvcSmm.

Insyde Advisory #3 - Insyde published an advisory that describes an Smm RAM corruption vulnerability in their IhisiServicesSmm.

Insyde Advisory #4 - Insyde published an advisory that describes an SMMRAM corruption vulnerability in their IhisiServicesSmm.

Insyde Advisory #5 - Insyde published an advisory that describes a malformed pointer vulnerability in their IhisiServicesSmm.

Insyde Advisory #6 - Insyde published an advisory that discusses a buffer underflow vulnerability in their MdeModulePkg/PiSmmCore.

Insyde Advisory #7 - Insyde published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in their NetworkPkg/IScsiDxe.

Insyde Advisory #8 - Insyde published an advisory that describes a buffer overflow vulnerability in their IhisiSmm.

Meinberg Advisory - Meinberg published an advisory that discusses five NTP vulnerabilities reported by spwpun.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes an exposure of sensitive system information to unauthorized actor vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a TOCTOU race condition vulnerability in their GlobalProtect App.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an improper handling of exceptional conditions vulnerability in their PAN-OS.

Phoenix Contact Advisory - Phoenix Contact published an advisory that describes a path traversal vulnerability in their ENERGY AXC PU, SMARTRTU AXC and Infobox products.

Sick Advisory - Sick published an advisory that describes a use of obsolete function vulnerability in their  Flexi Soft and Flexi Classic Gateways products.

Tanzu Advisory #1 - Tanzu published an advisory that discusses six Ubuntu vulnerabilities that affect the Tanzu Operations Manager.

Tanzu Advisory #2 - Tanzu published an advisory that discusses an integer overflow or wraparound vulnerability in their Platform Automation Toolkit and Operations Manager products.

Tanzu Advisory #3 - Tanzu published an advisory that discusses an integer overflow or wraparound vulnerability in their Greenplum for Kubernetes product.

Tanzu Advisory #4 - Tanzu published an advisory that discusses eight Ubuntu vulnerabilities in the Tanzu Greenplum for Kubernetes product. Tanzu.

Tanzu Advisory #5 - Tanzu published an advisory that discusses two Ubuntu vulnerabilities in the Tanzu Isolation Segment, Operations Manager and Tanzu Application Service products.

Tanzu Advisory #6 - Tanzu published an advisory that discusses an interpretation conflict vulnerability in the Tanzu Isolation Segment and Tanzu Application Service products.

Tanzu Advisory #7 - Tanzu published an advisory that discusses three Ubuntu vulnerabilities in the Tanzu Isolation Segment and Tanzu Application Service products.

Tanzu Advisory #8 - Tanzu published an advisory that discusses two Ubuntu vulnerabilities in the Tanzu Tanzu Isolation Segment, Operations Manager and Tanzu Application Service products.

Tanzu Advisory #9 - Tanzu published an advisory that discusses a denial of service vulnerability in their Platform Automation Toolkit.

Wireshark Advisory #1 - Wireshark published an advisory that describes a packet injection vulnerability in their RPCoRDMA dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes a packet injection vulnerability in their LISP dissector.

Wireshark Advisory #3 - Wireshark published an advisory that describes a packet injection vulnerability in their GQUIC dissector. Wireshark has new versions that mitigate the vulnerability.

 

For more details about these disclosures, including links to third-party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-afc - subscription required.

Saturday, April 16, 2022

Review – Public ICS Disclosures – Week of 4-9-22 – Part 1 –

With this being the 2nd Tuesday weekend, we will need two parts to look at all of the ICS disclosures. For Part 1 we have 23 vendor disclosures from ABB (3), Bentley (8), CODESYS, GE Healthcare, HMS, HPE, Palo Alto Networks (3), Phoenix Contact (3), Tanzu, and VMware. We also have five vendor updates from GE Healthcare, Hitachi Energy (2), and Palo Alto Networks (2). Then there are four researcher reports for products from PositiveGrid, and Delta Controls (3). Finally, we have three exploits for products from Franklin Fueling, Siemens, Spring.

Part 2 will look at the Schneider and Siemens disclosures published on Tuesday.

ABB Advisory #1 - ABB published an advisory discussing two vulnerabilities (one with known exploits) in their ARM600 M2M Gateway.

ABB Advisory #2 - ABB published an advisory describing a security bypass vulnerability in their Arctic Wireless Gateway.

ABB Advisory #3 - ABB published an advisory discussing the INCONTROLLER ICS attack tools.

Bentley Advisory #1 - Bentley published an advisory describing two vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory describing four vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory describing five vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #4 - Bentley published an advisory describing two vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #5 - Bentley published an advisory describing eleven vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #6 - Bentley published an advisory describing an out-of-bounds write vulnerability in their MicroStation and MicroStation-based applications.

Bentley Advisory #7 - Bentley published an advisory describing three vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #8 - Bentley published an advisory describing two vulnerabilities in their MicroStation and MicroStation-based applications.

CODESYS Advisory - CODESYS published an advisory discussing the INCONTROLLER ICS attack tools.

GE Healthcare Advisory - GE Healthcare published an advisory discussing the SpringShell vulnerability.

HMS Advisory - HMS published an advisory discussing the INFRA:HALT vulnerabilities.

HPE Advisory - HPE published an advisory describing a denial of service vulnerability in their Integrated Lights-Out 4 (iLO 4) products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory describing an improper handling of exceptional conditions vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory describing a product disruption vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory describing an information exposure through log files vulnerability in their Cortex XDR agent.

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory discussing 56 vulnerabilities in their AXC F x152 LTS.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory discussing an infinite loop vulnerability in their FL MGUARD, TC MGUARD, mGuard Device Manager and FL WLAN devices.

Phoenix Contact Advisory #3 - Phoenix Contact published an advisory discussing an HTTP request smuggling vulnerability in their mGuard Device Manager.

Tanzu Advisory - Tanzu published an advisory describing a data binding rule vulnerability in their Spring Framework products.

NOTE: This is related to the SpringShell vulnerability.

VMware Advisory - VMware published an advisory describing a remote code execution vulnerability in their Cloud Director product.

GE Healthcare Update - GE Healthcare published an update discussing the DirtyPipe vulnerability.

Hitachi Energy Update #1 - Hitachi Energy published an update for their XMC20 advisory that was originally published on November 23rd, 2021.

Hitachi Energy Update #2 - Hitachi Energy published an update for their FOX61x XMC20 advisory that was originally published on November 23rd, 2021.

Palo Alto Networks Update #1 - Palo Alto Networks published an update for their OpenSSL advisory that was originally published on March 31st, 2022.

Palo Alto Networks Update #2 - Palo Alto Networks published an update for their Spring Shell advisory that was originally published on March 31st, 2022.

PositiveGrid Report - Tenable published a report list six vulnerabilities in the PositiveGrid Spark API.

Delta Controls Report - Zero Science Labs published three reports about vulnerabilities in the Delta Controls enteliTOUCH building controllers.

Franklin Fueling Exploit - Momen Eldawakhly published an exploit for a local file inclusion vulnerability in the Franklin Fueling Systems Colibri Controller Module.

Siemens Exploit - Sec-consult published an exploit for two vulnerabilities in the Siemens A8000 CP-8050/CP-8031 SICAM WEB.

SpringShell Exploit - Mike Pickard published an exploit for the SpringShell vulnerability.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-3c2 - subscription required.

Tuesday, December 14, 2021

Review - Public ICS Disclosures - Log4Shell Advisories – 12-14-21

Today I am taking an out-of-band look at ICS vendor disclosures for the Log4Shell vulnerability. I have not looked at my list of medical device vendors for this post, I may look at those later this week. For this post we have 20 vendor disclosures from Aruba, Broadcom, CODESYS, Dell, GE (2), HMS (5), HPE, Hitachi Energy, Johnson Controls, QNAP, Rockwell, Ruckus, SonicWall (update), VMware and Wind River. I am using a slightly different format for this post, separating advisories into four groups; not affected, still looking, affected products list, and mitigation.

Not Affected

CODESYS published a notice that none of their products are affected.

HMS published an advisory reporting that their Argos and HMS Hub web services are not affected.

HMS published an advisory reporting that their Ixxat products are not affected.

Vendors Still Looking at the Vulnerability

GE published a generic Log4Shell advisory.

GE published an advisory.

HMS published an advisory for their Anybus product line.

HMS published an advisory for their WEBfactory product line.

Hitachi Energy published an advisory.

Meinberg published an advisory.

QNAP published an advisory.

Johnson Controls published an advisory.

Vendors With Affected Product Lists

Aruba published an advisory.

HPE published an advisory.

Ruckus published an advisory.  

SonicWall published an update for an advisory that was originally published on December 10th, 2021.

Wind River published an advisory.

Vendors With Mitigation Measures

Broadcom published an advisory.

Dell published an advisory for their Dell Wyse Management Suite.

HMS published an advisory for their EWON products.

Rockwell published an advisory.

VMware published an update for their advisory was originally published on December 10th, 2021.

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-log4shell - subscription required.

 
/* Use this with templates/template-twocol.html */