Showing posts with label Hikvision. Show all posts
Showing posts with label Hikvision. Show all posts

Saturday, March 21, 2026

Review – Public ICS Disclosures – Week of 3-14-26

This is a relatively light disclosure week. We have bulk vendor disclosures from QNAP (5). We have additional 10 vendor disclosures from Dassault Systems, Dell, HPE (3), Philips, Pheonix Contact, Rockwell Automation, Splunk, and TP-Link. We have bulk vendor updates from HP (6). There are two additional vendor updates from Dell and Siemens. Finally, we have 11 researcher reports for products from Hikvision and TP-Link (10).

Bulk Vendor Disclosures – QNAP

Vulnerability in QVR Pro

Multiple Vulnerabilities in QuNetSwitch (ADRA NDR),

Vulnerability in Media Streaming Add-on,  

Multiple Vulnerabilities in QuRouter (PWN2OWN 2025), and

Vulnerability in QuFTP Service.

Advisories

Dassault Advisory - Dassault published an advisory that describes a code injection vulnerability in their SOLIDWORKS Desktop.

Dell Advisory - Dell published an advisory that describes three vulnerabilities in their ThinOS 10 product.

HPE Advisory #1 - HPE published an advisory that discusses four vulnerabilities in their B-Series SANnav Management Portal product.

HPE Advisory #2 - HPE published an advisory that discusses seven vulnerabilities in their SAN Switches.

HPE Advisory #3 - HPE published an advisory that discusses a stack-based buffer overflow vulnerability in their Telco Service Orchestrator.

Philips Advisory - Philips published an advisory that discussed a Java security library vulnerability.

Pheonix Contact Advisory - Pheonix Contact published an advisory that discusses eight vulnerabilities in their FL SWITCH product lines.

Rockwell Advisory - Rockwell published an advisory that discusses a potential threat actor that is actively targeting Rockwell Automation controllers.

Splunk Advisory - Splunk published an advisory that discusses an improper check for unusual or exceptional conditions vulnerability in their Universal Forwarder product.

TP-Link Advisory - TP-Link published an advisory that describes two vulnerabilities in their TP-Link Archer AX53 product.

Bulk Vendor Updates – HP

Intel NPU Driver February 2026 Security Update,

Intel Chipset Firmware August 2025 Security Update,

Intel NPU Driver November 2025 Security Update,

Intel Processor Stream Cache August 2025 Security Update,

Intel Chipset Firmware February 2026 Security Update,

Intel Graphics Software August 2025 Security Update

Updates

Dell Update - Dell published an update for their Wyse Management Suite advisory that was originally published on February 24th, 2026.

Siemens Update - Siemens published an update for their SIMATIC S7-1500 advisory that was originally published on March 10th, 2026, and most recently updated on March 13th, 2026.

Researcher Reports

Hikvision Report - Cisco Talos published a report that describes a stack-based buffer overflow vulnerability (with proof-of-concept code) in the Hikvision Ultra Face Recognition Terminal.

TP-Link Reports - Cisco Talos published ten reports describing vulnerabilities in the TP-Link Archer AX53 AX3000 Dual Band Gigabit Wi-Fi 6 Router.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-632 - subscription required. 

Friday, March 6, 2026

CISA Adds Hikvision Vulnerability KEV Catalog -3-5-26

Yesterday CISA announced that it had added an improper authentication vulnerability in multiple Hikvision IP cameras to the CISA Known Exploited Vulnerabilities (KEV) catalog. Hikvision reported the vulnerability in March 2017. ICS-CERT published an advisory for the vulnerability in May 2017. In January 2025 FortiNet published a report of attempts to exploit the vulnerability. In September 2025 the SANS Internet Storm Center published a report about attempts to exploit the vulnerability.

CISA ordered federal agencies using the affected equipment to apply “mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.” A deadline of March 26th, 2026 has been applied.

Interestingly §889 of the 2019 National Defense Authorization Act (PL 115-232, 132 STAT. 1917) prohibited federal agencies from using ‘covered telecommunications equipment’ from Hikvision. So, this CISA directive may have very limited application within the federal government.

Sunday, July 6, 2025

Review – Public ICS Disclosures – Week of 7-28-25 – Part 2

For Part 2 we have three additional vendor disclosures from Fuji Electronic and Westermo (2). There are also seven vendor updates from Dell, Delta Electronics (3), Palo Alto Networks (2), and SonicWall. Finally, we have two researcher reports for vulnerabilities in products from Hikvision.

Advisories

Fuji Advisory - JP-CERT published an advisory that describes a heap-based buffer overflow vulnerability in the Fuji V-SFT and TELLUS products.

Westermo Advisory #1 - Westermo published an advisory that describes an OS command injection vulnerability in their WeOS 5 product.

Westermo Advisory #2 - Westermo published an advisory that describes an insertion of sensitive information into a log file vulnerability in their WeOS 5 product.

Updates

Dell Update - Dell published an update for their ThinOS advisory that was originally published on March 4th, 2025, and most recently updated on April 7th, 2025.

Delta Update #1 - Delta published an update for their mydeltasolar website advisory that was originally published on November 29th, 2022.

Delta Update #2 - Delta published an update for their iacommunication web page advisory that was originally published on February 10th, 2022.

Delta Update #3 - Delta published an update for their deltaww.com advisory that was originally published on March 9th, 2023.

Palo Alto Networks Update #1 - PAN published an update for their Authenticated Admin Command Injection advisory that was originally published on June 11th, 2025, and most recently updated on June 24th, 2025.

Palo Alto Networks Update #2 -n PAN published an update for their Traffic Information Disclosure advisory that was originally published on June 11th, 2025.

SonicWall Update - SonicWall published an update for their SMA100 SSL-VPN advisory that was originally published on December 4th, 2024, and most recently updated on April 29th, 2025.

Researcher Reports

Hikvision Report #1 - VulnCheck published a report about a deserialization of untrusted data vulnerability (with publicly available exploit) in the Hikvision HikCentral product.

Hikvision Report #2 - VulnCheck published a report about a path traversal vulnerability in the Hikvision Streaming Media Management Server.

 

For more information on these disclosures, including links to researcher reports and exploits – see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-ac5 - subscription required.

Saturday, November 2, 2024

Review – Public ICS Disclosures – Week of 10-25-24 – Part 1

This week, for Part 1, we have 20 vendor disclosures from Broadcom (8), Beckhoff, Bosch, GE Vernova (2), Hikvision, Hitachi Energy (2), HP (3), HPE, and Omron.

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses a function call with incorrect argument type vulnerability in their SANnav product.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an integer overflow or wrap around vulnerability in their SANnav product.

Broadcom Advisory #3 - Broadcom published an advisory that discusses nine vulnerabilities (three with publicly available exploits) in their Fabric OS, SANnav, and ASCG products.

Broadcom Advisory #4 - Broadcom published an advisory that discusses an incorrect resource transfer between spheres vulnerability in their SANnav product.

Broadcom Advisory #5 - Broadcom published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their SANnav product.

Broadcom Advisory #6 - Broadcom published an advisory that discusses an incomplete cleanup vulnerability in their SANnav product.

Broadcom Advisory #7 - Broadcom published an advisory that discusses three inadequately described vulnerabilities in their SANnav product.

Broadcom Advisory #8 - Broadcom published an advisory that discusses six vulnerabilities in their SANnav products.

Beckhoff Advisory - CERT-VDE published an advisory that describes an OS command injection vulnerability in the Beckhoff TwinCAT Package Manager.

Bosch Advisory - Bosch published an advisory that describes an uncontrolled resource consumption vulnerability in the PROFINET stack implementation of the IndraDrive.

GE Vernova Advisory #1 - GE published an advisory that discusses two vulnerabilities in Control Server installations that use VMware vCenter Server.

GE Vernova Advisory #2 - GE published an advisory that describes a side-channel key recovery vulnerability in YubiKey’s in customers using Xona devices and those using YubiKey authentication for certain HMI deployments.

Hikvision Advisory - JP- CERT published an advisory that announces firmware updates for multiple network cameras as a security enhancement, changing the behavior to communicate with Dynamic DNS services, to prevent cleartext transmission.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes two vulnerabilities in their TRO600 series products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses two vulnerabilities (both with publicly available exploits) in their MSM product web services.

HP Advisory #1 - HP published an advisory that discusses the PixieFail vulnerabilities.

HP Advisory #2 - HP published an advisory that discusses 353 vulnerabilities in their ThinPro product.

HP Advisory #3 - HP published an advisory that describes an out-of-bounds write vulnerability in their Smart Universal Printing Driver.

HPE Advisory - HPE published an advisory that discusses the regreSSHion vulnerability.

Omron Advisory - Omron published an advisory that describes an improper authorization vulnerability in their Sysmac Studio product.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-25a - subscription required.

Saturday, October 19, 2024

Review – Public ICS Disclosures – Week of 10-12-24 – Part 1

This week we have vendor disclosures from Belden, Bosch, Dassault Systèmes (2), Helmholtz (2), Hikvision, HP (3), HPE (3), MB Connect (2), Meinberg, Moxa, Philips (2), and Sick.

Advisories

Belden Advisory - Belden published an advisory that describes a heap overflow vulnerability (with publicly available exploit) in their Hirschman HilCOS product line.

Bosch Advisory - Bosch published an advisory that describes an unrestricted resource consumption vulnerability in their VMS Central Server.

Dassault Systèmes Advisory #1 – Dassault Systèmes published an advisory that describes an authorization bypass through user-controlled keys vulnerability in their 3DSwymer.

Dassault Systèmes Advisory #2 – Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their ENOVIA product.

Helmholtz Advisory #1 - CERT-VDE published an advisory that describes two vulnerabilities in multiple Helmholtz products.

Helmholtz Advisory #2 - CERT-VDE published an advisory that describes five vulnerabilities in the Helmholtz REX100 industrial router.

Hikvision Advisory - Hikvision published an advisory that describes three vulnerabilities in their HikCentral product series.

HP Advisory #1 - HP published an advisory that describes a missing authentication for critical function vulnerability in their DesignJet products.

HP Advisory #2 - HP published an advisory that discusses an incorrect behavior order vulnerability in their SMI Transfer Monitor.

HP Advisory #3 - HP published an advisory that discusses 12 vulnerabilities in multiple HP products.

HPE Advisory #1 - HPE published an advisory that discusses a code injection vulnerability in their Cray and ProLiant XL Servers.

HPE Advisory #2 - HPE published an advisory that discusses an incomplete filtering of special elements vulnerability in their ProLiant DX Servers.

HPE Advisory #3 - HPE published an advisory that discusses an insufficient control flow management vulnerability in their ProLiant DX Servers.

MB Connect Advisory #1 - CERT-VDE published an advisory that describes two vulnerabilities in multiple MB Connect products.

MB Connect Advisory #2 - CERT-VDE published an advisory that describes five vulnerabilities in the mbNET.mini product.

Meinberg Advisory - Meinberg published an advisory that discusses five vulnerabilities in their LANTIME product.

Moxa Advisory - Moxa published an advisory that describes two vulnerabilities in their MXsecurity Series products.

Philips Advisory #1 - Philips published an advisory that discusses two recent MS Windows vulnerabilities (CVE-2024-43572 and CVE-2024-43573) listed on CISA’s Known Exploited Vulnerabilities catalog.

Philips Advisory #2 - Philips published an advisory that discusses two recent Cisco vulnerabilities (CVE-2024-20393 and CVE-2024-20470).

Sick Advisory - Sick published an advisory that describes a use of hard-coded credentials vulnerability in multiple Sick products.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-4a8 - subscription required.

Sunday, October 13, 2024

Review – Public ICS Disclosures – Week of 10-5-24 – Part 2

For Part 2 we have six additional vendor disclosures from SonicWall, Supermicro, VMware (2), and Wireshark (2). There are also 22 vendor updates from FortiGuard, HP, HPE, Schneider, and Siemens (18). There are also ten researcher reports on vulnerabilities in products from ABB. Finally, we have two exploits for products from Hikvision and Palo Alto Networks.

Advisories

SonicWall Advisory - SonicWall published an advisory that describes three vulnerabilities in their SMA1000 Connect Tunnel Windows Client.

Supermicro Advisory - Supermicro published an advisory that discusses the Terrapin-Attack vulnerability.

VMware Advisory #1 - Broadcom published an advisory that describes three vulnerabilities in the VMware Cloud Foundation and VMware NSX products.

VMware Advisory #2 - Broadcom published an advisory that describes two vulnerabilities in the VMware Avi Load Balancer.

Wireshark Advisory #1 - Wireshark published an advisory that describes a missing initialization of a variable vulnerability in their ITS dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes an improper handling of missing values vulnerability in their AppleTalk and Reload framing dissectors.

Updates

FortiGuard Update #1 - FortiGuard published an update for their Buffer overflow in fgfmd advisory that was originally published on June 11th, 2024.

HP Update - HP published an update for their AMD Graphics Driver advisory that was originally published on August 13th, 2024.

HPE Update - HP published an update for their Blast-Radius advisory that was originally published on July 9th, 2024, and most recently updated on August 30th, 2024.

Schneider Update - Schneider published an update for their Modicon M340 Controller advisory that was originally published on April 12th, 2024, and most recently updated on February 14th, 2023.

Siemens Update #1 - Siemens published an update for their User Management Component advisory that was originally published on December 12th, 2023, and most recently updated on September 10th, 2024.

Siemens Update #2 - Siemens published an update for their Industrial Products advisory that was originally published on May 14th, 2024, and most recently updated on September 10th, 2024.

Siemens Update #3 - Siemens published an update for their LOGO! 8 BM Devices advisory that was originally published on October 11th, 2022, and most recently updated on September 10th, 2024.

Siemens Update #4 - Siemens published an update for their LOGO! V8.3 BM Devices advisory that was originally published on August 13th, 2024, and most recently updated on September 10th, 2024.

Siemens Update #5 - Siemens published an update for their LOGO! V8.3 BM Devices advisory that was originally published on December 12th, 2023, and most recently updated on September 9th, 2024.

Siemens Update #6 - Siemens published an update for their LOGO! 8 BM advisory that was originally published on March 9th, 2021, and most recently updated on September 10th, 2024.

Siemens Update #7 - Siemens published an update for their OPC UA Implementations advisory that was originally published on September 12th, 2023, and most recently updated on July 9th, 2024.

Siemens Update #8 - Siemens published an update for their RUGGEDCOM APE1808 Devices advisory that was originally published on July 9th, 2024, and most recently updated on September 10th, 2024.

Siemens Update #9 - Siemens published an update for their SIMATIC SCADA and PCS 7 systems advisory that was originally published on September 10th, 2024.

Siemens Update #10 - Siemens published an update for their NUCLEUS:13 advisory that was originally on December 14th, 2021, and most recently updated on November 8th, 2022.

Siemens Update #11 - Siemens published an update for their RUGGEDCOM APE1808 Devices advisory that was originally published on April 9th, 2024, and most recently updated on September 10th, 2024.

Siemens Update #12 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2023, and most recently updated on August 13th, 2024.

Siemens Update #13 - Siemens published an update for their RUGGEDCOM APE1808 Devices that was originally published on March 12th, 2024.

Siemens Update #14 - Siemens published an update for their RUGGEDCOM APE1808 Devices advisory that was originally published on July 9th, 2024, and most recently updated on August 13th, 2024.

Siemens Update #15 - Siemens published an update for their OPC Foundation Local Discovery Server advisory that was originally published on May 10th, 2022, most recently updated on April 11th, 2023.

Siemens Update #16 - Siemens published an update for their Mendix Runtime advisory that was originally published on March 8th, 2022, and most recently updated on May 14th, 2024.

Siemens Update #17 - Siemens published an update for their User Management Component advisory that was originally published on September 10th, 2024.

Researcher Reports

ABB Reports - Zero Science published ten reports about vulnerabilities (exploits are available) in the ABB Cylon Aspect building energy management system.

Exploits

Hikvision Exploit - Indoushka published an exploit for a cross-site request forgery in the Hikvision IP Cameras.

Palo Alto Networks Exploit - Johannes Greil and Michael Baer published an exploit for a privilege escalation vulnerability in the Palo Alto Networks GlobalProtect product.

 

For more information on these disclosures, including links to researcher reports, and exploits, as well as brief descriptions of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-5bd - subscription required.

Saturday, April 6, 2024

Review – Public ICS Disclosures – Week of 3-30-24

This week we have five vendor disclosures about the XZ Utils vulnerability from Broadcom, Palo Alto Networks, Philips, QNAP, and WatchGuard. We have fourteen additional vendor disclosures from ABB, BD, Broadcom (2), Cisco, Hikvision, HP, HPE (4), Palo Alto Networks, Philips, and VMWare. There are four vendor updates from Eaton, HP (2), and HPE. We have five researcher reports for vulnerabilities in products from Open Automation Software (4) and Positron. Finally, we have an exploit for products from Petrol Pump.

XZ Utils Advisories

Broadcom published an advisory that discussed the XZ Utils vulnerability.

Palo Alto Networks published an advisory that discussed the XZ Utils vulnerability.

Philips published an advisory that discussed the XZ Utils vulnerability.

QNAP published an advisory that discussed the XZ Utils vulnerability.

WatchGuard published an advisory that discussed the XZ Utils vulnerability.

Advisories

ABB Advisory - ABB published an advisory that describes an improper input validation vulnerability in the Virtual PNI API in their S+ Engineering product.

BD Advisory - BD published an advisory that discusses an improper privilege management vulnerability in a number of their products.

Broadcom Advisory #1 - Broadcom published an advisory that describes an OS command injection vulnerability in their Brocade Fabric OS product.

Broadcom Advisory #2 - Broadcom published an advisory that describes an origin validation error vulnerability in their Brocade Fabric OS product.

Cisco Advisory - Cisco published an advisory that describes two vulnerabilities in their Emergency Responder product.

Hikvision Advisory - Hikvision published an advisory that describes three vulnerabilities in their NVR devices.

HP Advisory - HP published an advisory that describes an improper access control vulnerability in their CCX devices.

HPE Advisory #1 - HPE published an advisory that discusses eight vulnerabilities (three with known exploits) in their Unified OSS Console Assurance Monitoring product.

HPE Advisory #2 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/ML/SY/RL/XL/Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that describes a privilege escalation vulnerability in their MSA SAN Storage VSS Provider and CAPI Proxy Software.

HPE Advisory #4 - HPE published an advisory that describes an unauthorized access to files vulnerability in their NonStop Web ViewPoint Enterprise software.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses eight third-party vulnerabilities that could be associated with their Prisma SD-WAN ION product.

Philips Advisory - Philips published an advisory that discusses a use-after-free vulnerability in multiple Philips products.

VMware Advisory - VMware published an advisory that describes three vulnerabilities in their SD-WAN Edge and SD-WAN Orchestrator products.

Updates

Eaton Update - Eaton published an update for their Apache Log4j advisory that was originally published on December 14th, 2021 and most recently updated on January 31st, 2022.

HP Update #1 - HP published an update for their OfficeJet Pro advisory that was originally published on March 20th, 2024.

HP Update #2 - HP published an update for their AMD Graphics Driver advisory that was originally published on November 21st, 2023.

HPE Update - HPE published an update for their SimpliVity Servers advisory that was originally published on February 15th, 2024.

Researcher Reports

Open Automation Software Reports - Talos published four reports for individual vulnerabilities in the OAS Platform product.

Positron Report - Zero Science published a report about an authentication bypass vulnerability in the Positron TRA7005 series broadcast signal processor.

Exploits

Petrol Pump Exploit - Sandeep Vishwakarma published an exploit for a file upload vulnerability in the Petrol Pump Management software.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-671 - subscription required. 

Saturday, March 30, 2024

Review – Public ICS Disclosures – Week of 3-23-24 – Part 2

For Part 2 we have eight additional vendor disclosures from SEL, SonicDICOM, Splunk (4), Watchguard, and Wireshark. There are also five vendor updates from ELECOM, Hitachi Energy (3), and HP. We also have three researcher reports for vulnerabilities in products from Hikvision, Kunbus, and Uniview. Finally, we have two exploits for products from Dell and Watchguard.

Advisories

SEL Advisory - SEL published a notification of a new version of their SEL-5813 Backup and Recovery Tool (BaRT) which includes a cybersecurity enhancement.

SonicDICOM Advisory - JP Cert published an advisory that discusses a use after free vulnerability in the SonicDICOM Media Viewer.

Splunk Advisory #1 - Splunk published an advisory that describes an insertion of sensitive information into log files vulnerability in the Debug Log in their Enterprise product.

Splunk Advisory #2 - Splunk published an advisory that describes an improper input validation vulnerability in the Dashboard Examples Hub of their Enterprise product.

Splunk Advisory #3 - Splunk published an advisory that discusses four vulnerabilities in their Enterprise product.

Splunk Advisory #4 - Splunk published an advisory that discusses two vulnerabilities in their Universal Forwarder product.

Watchguard Advisory - Watchguard published an advisory that describes a code injection vulnerability in their AuthPoint Password Manager extension for MacOS Safari.

Wireshark Advisory - Wireshark published an advisory that describes a mismatched memory management routines vulnerability in their T.38 dissector.

Updates

ELECOM Update - ELECOM published an update for their Wireless LAN routers advisory that was originally published on February 20th, 2024.

Hitachi Energy Update #1 - Hitachi Energy published an update for their RTU500 series products advisory that was originally published on December 19th, 2023 and most recently updated on February 27th, 2024.

Hitachi Energy Update #2 - Hitachi Energy published an update for their RTU500 series products advisory that was originally published on November 28th, 2023 and most recently updated on February 27th, 2024.

Hitachi Energy Update #3 - Hitachi Energy published an update for their RTU500 series products advisory that was originally published on April 25th, 2023 and most recently updated on February 27th, 2024.

HP Update - HP published an update for their HP Trusted Platform Module advisory that was originally published on June 8th, 2018.

Researcher Reports

Hikvision Report - IOActive published a report for a classic buffer overflow vulnerability in the Hikvision DS-7732NI-I4(B) network video recorder.

Kunbus Report - IOActive published a report of an off-by-one error vulnerability {that is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog} in the Kunbus Revolution PI industrial PC.

Uniview Report - SSD-Disclosure published a report for an authentication bypass vulnerability in selected Uniview IP Cameras.

Exploits

Dell Exploit - Amirhossein Bahramizadeh published an exploit for an improper access control vulnerability in the Dell Security Management Server.

WatchGuard Exploit - Charles FOL published a Metasploit module for a buffer overflow vulnerability (that is on CISA’s KEV catalog) in the WatchGuard Firebox and XTM appliances.

 

For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-ede - subscription required.

Saturday, March 2, 2024

Review – Public ICS Disclosures – Week of 2-26-24

This week we have 12 vendor disclosures from Aruba Networks, CODESYS, Dell, Festo, Hikvision, Hitachi Energy, HP, Moxa, Philips, SMA, Wiesemann & Theis, and VMware. There are four vendor updates from Hitachi Energy. There is a researcher report for a vulnerability in products from Qognify. Finally, we have three exploits for products from Automatic Systems (2), and Saflok.

Advisories

Aruba Advisory - Aruba published an advisory that describes ten vulnerabilities in their ClearPass Policy Manager product.

CODESYS Advisory - CODESYS published an advisory that describes an OS command injection vulnerability in their Control V3 on Linux and QNX operating systems product.

Dell Advisory - Dell published an advisory that discusses TPM Interposer BitLocker research.

Festo Advisory - CERT-VDE published an advisory that discusses 140 vulnerabilities in the Festo MES PCs.

Hikvision Advisory - Hikvision published an advisory that describes two improper server-side validation vulnerabilities in their HikCentral Professional product.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses the Terrapin-Attack vulnerability.

HP Advisory - HP published an advisory that discusses 133 vulnerabilities in their ThinPro product. These are third-party vulnerabilities.

Moxa Advisory - Moxa published an advisory that describes a confused deputy vulnerability in their EDS-4000/G4000 Series products.

Philips Advisory - Philips published an advisory that discusses a use after free vulnerability in their EarlyVue VS30.

SMA Advisory - Incibe-CERT published an advisory that describes two vulnerabilities in the SMA Cluster Controller and Sunny Webbox products.

Wiesemann & Theis Advisory - CERT-VDE published an advisory that describes an unquoted search path vulnerability in multiple Wieseman & Theis products.

VMware Advisory - VMware published an advisory that describes an out-of-bounds read vulnerability in their Workstation Pro and Fusion products.

Updates

Hitachi Energy Update #1 - Hitachi Energy published an update for their RTU500 advisory that was originally published on December 19th, 2023.

Hitachi Energy Update #2 - Hitachi Energy published an update for their RTU500 advisory that was originally published on November 28th, 2023 and most recently updated on December 13th, 2023.

Hitachi Energy Update #3 - Hitachi Energy published an update for their OpenSSL advisory that was originally published on April 25th, 2023.

Hitachi Energy Update #4 - Hitachi Energy published an update for their IEC 61850 MMS-Server advisory that was originally published on February 14th, 2023.

Researcher Reports

Qognify Report - SEC Consult published a report that describes an uncontrolled search path element in the Qognify VMS Client Viewer.

Exploits

Automatic Systems Exploit #1 - Marcin Kozlowski published an exploit for a path traversal vulnerability in the Automatic-Systems SOC FL9600 FastLine.

Automatic Systems Exploit #2 - Marcin Kozlowski published an exploit for a use of hard-coded credentials vulnerability in the Automatic-Systems SOC FL9600 FastLine product.

Saflok Exploit - A51199deefa2c2520cea24f746d899ce published an exploit for a key derivativation vulnerability in the Saflok System 6000.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-584 - subscription required.

Saturday, November 25, 2023

Review – Public ICS Disclosures – Week of 11-18-23 – Part 1

This week we have 20 vendor disclosures from Eaton, FortiGuard (3), Hikvision (3), HP (9), HPE (3), and Meinberg.

Advisories

Eaton Advisories - Eaton published an advisory that describes an improper access control vulnerability in multiple Eaton products.

FortiGuard Advisory #1 - FortiGuard published an advisory that discusses two vulnerabilities in their FortiGate products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper validation of integrity check value vulnerability in their FortiOS and FortiProxy products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a numeric truncation error in their FortiOS and FortiProxy SSL VPN.

Hikvision Advisory #1 - Hikvision published an advisory that describes a buffer overflow vulnerability in their NVR/DVR Devices.

Hikvision Advisory #2 - Hikvision published an advisory that describes two vulnerabilities in their LocalServiceComponents application.

Hikvision Advisory #3 - Hikvision published an advisory that describes an authentication bypass vulnerability in multiple Hikvision products.

HP Advisory #1 - HP published an advisory that discusses an incorrect permission assignment for critical resource vulnerability in multiple HP computers.

HP Advisory #2 - HP published an advisory that discusses an uncontrolled search path element vulnerability in multiple HP computers.

HP Advisory #3 - HP published an advisory that discusses five vulnerabilities in multiple HP computers.

HP Advisory #4 - HP published an advisory that discusses an improper access control vulnerability in multiple HP workstations.

HP Advisory #5 - HP published an advisory that discusses seven vulnerabilities in multiple HP computers.

HP Advisory #6 - HP published an advisory that discusses an improper access control vulnerability in multiple HP computers.

HP Advisory #7 - HP published an advisory that discusses an uncontrolled search path element vulnerability in multiple HP computers.

HP Advisory #8 - HP published an advisory that discusses two improper input validation vulnerabilities in multiple HP computers.

HP Advisory #9 - HP published an advisory that discusses four vulnerabilities in multiple HP computers.

HPE Advisory #1 - HPE published an advisory that discuss an improper or unexpected behavior of the INVD instruction vulnerability in their ProLiant DL/DX/XL servers.

HPE Advisory #2 - HPE published an advisory that discusses sequence of processor instructions leads to unexpected behavior vulnerability in their Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that discusses an improper certificate validation vulnerability in their UX OpenSSL product.

Meinberg Advisory - Meinberg published an advisory that discusses seven vulnerabilities in their Lantime product.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-dda - subscription required.

Thursday, October 12, 2023

Review – 18 Advisories and 1 Updates Published

Today, CISA’s NCCIC-ICS published 16 control system security advisories for products from Schneider, Advantech, Hikvision, Mitsubishi, Weintek, and Siemens (11) and two medical device security advisories for products from Santesoft. They also updated an advisory for products from PTC.

Siemens published one additional advisory (and 11 updates) on Tuesday that were not covered here. CISA no longer updates their Siemens advisories. I will discuss all them this weekend in my Public ICS Disclosure blog post.

Advisories

Schneider Advisory - This advisory describes a missing authentication for critical function vulnerability in the Schneider Interactive Graphical SCADA System (IGSS).

Advantech Advisory - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Advantech WebAccess product.

Hikvision Advisory - This advisory describes two vulnerabilities in the Hikvision Access Control and Intercom Products.

Mitsubishi Advisory - This advisory describes an improper authentication vulnerability in the Mitsubishi MELSEC-F Series main modules.

Weintek Advisory - This advisory describes three vulnerabilities in the Weintek cMT3000 CMI Web CGI.

Mendix Advisory - This advisory describes an observable discrepancy vulnerability in the Siemens Mendix Forgot Password Module.

Tecnomatix Advisory - This advisory describes seven vulnerabilities in the Siemens Tecnomatix Plant Simulation product.

SICAM Advisory #1 - This advisory describes a use of hard-coded credentials vulnerability in the Siemens CP-8050 and CP-8031 master modules.

SICAM Advisory #2 - This advisory describes an incorrect permission assignment for a critical resource vulnerability in the Siemens SICAM PAS/PQS.

SICAM Advisory #3 - This advisory describes a path traversal advisory vulnerability in the Siemens SICAM A8000 CP-8031 and CP-8050 master modules.

SINEC Advisory - This advisory describes two vulnerabilities in the Siemens SINEC NMS.

RUGGEDCOM Advisory - This advisory discusses seven vulnerabilities in the Siemens RUGGEDCOM APE1808.

Simcenter Advisory - This advisory describes a code injection vulnerability in the Siemens Simcenter Amesim product.

Xpedition Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Xpedition Layout Browser.

SCALANCE Advisory - This advisory discusses thirteen vulnerabilities in the Siemens SCALANCE W1750D.

SIMATIC Advisory - This advisory describes two vulnerabilities in the Siemens SIMATIC CP products.

Santesoft Advisory #1 - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante FFT Imaging.

Santesoft Advisory #2 - This advisory describes two vulnerabilities in the Santesoft Sante DICOM Viewer Pro.

Updates

PTC Update - This update provides additional information on an advisory that was originally published on August 31st, 2023.

 

For more information on these advisories, including lists of missing vulnerabilities, links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/18-advisories-and-1-updates-published - subscription required.

Saturday, July 22, 2023

Review – Public ICS Disclosures – Week of 7-15-22

This week we have nine vendor disclosures from Aqua eSolutions, Beldon, HP (2), SEL (2), Sierra Wireless, Splunk, and Zyxel. There are two vendor updates from AMI and HPE. We also have three researcher reports about vulnerabilities in products from Tesla. Finally, we have two exploits for products from ABB and Hikvision.

Advisories

Aqua Advisory - Incibe CERT published an advisory that describes a relative path traversal vulnerability in their Aqua Drive.

Belden Advisory - Beldon published an advisory that discusses an undescribed JavaSE vulnerability in several of their Belden and Hirschmann products.

HP Advisory #1 - HP published an advisory that discusses two vulnerabilities in their Security Manager and Web Jetadmin products.

HP Advisory #2 - HP published an advisory that describes an elevation of privilege vulnerability in their LaserJet Pro print products.

SEL Advisory #1 - SEL published a new version notice for their SEL-5030 acSELerator QuickSet software that addresses seven briefly described cybersecurity issues.

SEL Advisory #2 - SEL published a new version notice for their SEL-5036 acSELerator Bay Screen Builder Software that addresses a software validation issue.

Sierra Wireless Advisory - Sierra Wireless published an advisory that briefly discusses a Cl0p ransomware attack on a Sierra Wireless corporate server.

Splunk Advisory - Splunk published an advisory that discusses two vulnerabilities in their SOAR product.

Zyxel Advisory - Zyxel published an advisory that describes seven vulnerabilities in their firewall and WLAN controllers.

Updates

AMI Update - AMI published an update for their -MegaRAC SPX advisory that was originally published on July 5th, 2023.

HPE Update - HPE published an update for their ArubaOS-CX 8000 Series Switches advisory that was originally published on February 2nd, 2022.

Researcher Reports

Tesla Reports - The Zero Day Initiative published three reports about individual vulnerabilities in the Tesla Model 3 that were discovered as part of a Pwn2Own competition.

Exploits

ABB Exploit - Paul Smith published an exploit for an exposure of sensitive information to an unauthorized actor vulnerability in the ABB FlowX product.

Hikvision Exploit - Thurein Soe published an exploit for a command injection vulnerability in the Hikvision Hybrid SAN Ds-a71024 product.

Commentary

I would like to commend Sierra Wireless on their advisory about the potential consequences of their recent Cl0p ransomware attack. Ransomware attacks are a big problem, but frequently overlooked in attacks on vendors is that information may have been discovered by the attacker that could be used to exploit product vulnerabilities in their customers. Reports like this one provide customers a heads up about potential attacks on their equipment.

 

For more details about these disclosures, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-c81 - subscription required.

Saturday, July 8, 2023

Review – Public ICS Disclosures – Week of 7-1-23

This week we have eleven vendor disclosures from Aruba Networks, Bosch (2), Enphase, Frauscher Sensortechnik, Hikvision, Moxa, Softing (2), VMware and Zyxel. And we have 29 researcher reports for products from Panasonic (3), Milesight (25), and Siemens.

Advisories

Aruba Advisory - Aruba published an advisory that describes nine vulnerabilities in the Aruba OS products.

Bosch Advisory #1 - Bosch published an advisory that discusses two vulnerabilities in their FL MGUARD family devices.

Bosch Advisory #2 - Bosch published an advisory that discusses a missing authentication for critical function vulnerability in their SLC-0-GPNT00300 interface module.

Enphase Advisory - Enphase published an advisory that describes an OS command injection vulnerability in their Enphase IQ Gateway (Envoy).

Frauscher Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1.

Hikvision Advisory - Hikvision published an advisory that describes two vulnerabilities in their access control/intercom products.

Moxa Advisory - Moxa published an advisory that describes an observable response discrepancy vulnerability in their TN-5900 Series product.

Softing Advisory #1 - Softing published an advisory that describes two vulnerabilities in their OPC UA C++ SDK and Secure Integration Server.

Softing Advisory #2 - Softing published an advisory that describes an uncontrolled resource consumption vulnerability in a number of their products.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their SD-WAN (Edge) product.

Zyxel Advisory - Zyxel published an advisory that describes a classic buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Researcher Reports

Panasonic Reports - AWESEC published three reports describing individual vulnerabilities in the Panasonic Panasonic AiSEG2.

Milesight Reports - Talos Intelligence published 25 reports (some with multiple vulnerabilities) for the Milesight UR32L urvpn_client and MilesightVPN server.

Siemens Report - SEC Consult published a report describing the four vulnerabilities in the Siemens A8000 product.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-bcb - subscription required.

Saturday, April 15, 2023

Review – Public ICS Disclosures – Week of 4-8-23 – Part 1

And once again it is the Saturday after Cyber Tuesday. For Part 1, we have 34 vendor disclosures from B&R, Flexera, Hikvision, HMS, HP, HPE (3), Insyde (8), Meinberg, Palo Alto Networks (3), Phoenix Contact, Sick, Tanzu (9), and Wireshark (3).

NOTE: It has become obvious that FortiGuard has joined the ranks of organizations that report vulnerabilities en-mass on Cyber Tuesday. As such they will join Schneider and Siemens in being reported in a subsequent Part of the weekend’s Public ICS Disclosure.

Advisories

B&R Advisory - B&R published an advisory that discusses three vulnerabilities in their B&R VC4 Visualization product.

Flexera Advisory - Flexera published an advisory that discusses four vulnerabilities in their FlexNet Publisher product.

Hikvision Advisory - Hikvision published an advisory that describes an improper access control vulnerability in their Hybrid SAN/Cluster Storage products.

HMS Advisory - HMS published an advisory that discusses the INFRA:HALT vulnerabilities.

HP Advisory - HP published an advisory that discusses 31 vulnerabilities in their Device Manager product.

HPE Advisory #1 - HPE published an advisory that describes six disclosure of sensitive information vulnerabilities in their OneView product.

HPE Advisory #2 - HPE published an advisory that describes a disclosure of sensitive information vulnerable in their OneView "Migrate Server Hardware" Option.

HPE Advisory #3 - HPE published an advisory that describes two disclosure of sensitive information vulnerabilities in their OneView Global Dashboard.

Insyde Advisory #1 - Insyde published an advisory that describes a memory corruption vulnerability in their FTBS SMI Handler.

Insyde Advisory #2 - Insyde published an advisory that describes an insufficient input validation vulnerability in their ChipsetSvcSmm.

Insyde Advisory #3 - Insyde published an advisory that describes an Smm RAM corruption vulnerability in their IhisiServicesSmm.

Insyde Advisory #4 - Insyde published an advisory that describes an SMMRAM corruption vulnerability in their IhisiServicesSmm.

Insyde Advisory #5 - Insyde published an advisory that describes a malformed pointer vulnerability in their IhisiServicesSmm.

Insyde Advisory #6 - Insyde published an advisory that discusses a buffer underflow vulnerability in their MdeModulePkg/PiSmmCore.

Insyde Advisory #7 - Insyde published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in their NetworkPkg/IScsiDxe.

Insyde Advisory #8 - Insyde published an advisory that describes a buffer overflow vulnerability in their IhisiSmm.

Meinberg Advisory - Meinberg published an advisory that discusses five NTP vulnerabilities reported by spwpun.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes an exposure of sensitive system information to unauthorized actor vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a TOCTOU race condition vulnerability in their GlobalProtect App.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an improper handling of exceptional conditions vulnerability in their PAN-OS.

Phoenix Contact Advisory - Phoenix Contact published an advisory that describes a path traversal vulnerability in their ENERGY AXC PU, SMARTRTU AXC and Infobox products.

Sick Advisory - Sick published an advisory that describes a use of obsolete function vulnerability in their  Flexi Soft and Flexi Classic Gateways products.

Tanzu Advisory #1 - Tanzu published an advisory that discusses six Ubuntu vulnerabilities that affect the Tanzu Operations Manager.

Tanzu Advisory #2 - Tanzu published an advisory that discusses an integer overflow or wraparound vulnerability in their Platform Automation Toolkit and Operations Manager products.

Tanzu Advisory #3 - Tanzu published an advisory that discusses an integer overflow or wraparound vulnerability in their Greenplum for Kubernetes product.

Tanzu Advisory #4 - Tanzu published an advisory that discusses eight Ubuntu vulnerabilities in the Tanzu Greenplum for Kubernetes product. Tanzu.

Tanzu Advisory #5 - Tanzu published an advisory that discusses two Ubuntu vulnerabilities in the Tanzu Isolation Segment, Operations Manager and Tanzu Application Service products.

Tanzu Advisory #6 - Tanzu published an advisory that discusses an interpretation conflict vulnerability in the Tanzu Isolation Segment and Tanzu Application Service products.

Tanzu Advisory #7 - Tanzu published an advisory that discusses three Ubuntu vulnerabilities in the Tanzu Isolation Segment and Tanzu Application Service products.

Tanzu Advisory #8 - Tanzu published an advisory that discusses two Ubuntu vulnerabilities in the Tanzu Tanzu Isolation Segment, Operations Manager and Tanzu Application Service products.

Tanzu Advisory #9 - Tanzu published an advisory that discusses a denial of service vulnerability in their Platform Automation Toolkit.

Wireshark Advisory #1 - Wireshark published an advisory that describes a packet injection vulnerability in their RPCoRDMA dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes a packet injection vulnerability in their LISP dissector.

Wireshark Advisory #3 - Wireshark published an advisory that describes a packet injection vulnerability in their GQUIC dissector. Wireshark has new versions that mitigate the vulnerability.

 

For more details about these disclosures, including links to third-party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-afc - subscription required.

Saturday, December 24, 2022

Review – Public ICS Disclosures – Week of 12-17-22

This week we have an OpenSSL 3.0 disclosure from Palo Alto Networks. There are nine vendor disclosures from Dahua, Dell, DIGI, Hikvision, HPE, Microchip, Motorola Solutions, TandD, and Western Digital. Finally, there is a vendor update from Siemens.

OpenSSL. 3.0

Palo Alto Networks published an advisory discussing the OpenSSL 3.0 vulnerabilities.

Vendor Disclosures

Dahua Advisory - Dahua published an advisory that describes twelve vulnerabilities in a variety of Dahua products.

Dell Advisory - Dell published an advisory that describes nine vulnerabilities (includes 3 third-party vulnerabilities) in their Wyse Management Suite. 

DIGI Advisory - DIGI published an advisory that discusses the FragAttack vulnerabilities.

Hikvision Advisory - Hikvision published an advisory that describes an access control vulnerability in their wireless bridge products.

HPE Advisory #1 - HPE published an advisory that directory traversal vulnerability in their OfficeConnect 1820, and 1850 Switch Series.

HPE Advisory #2 - HPE published an advisory that describes a data injection vulnerability in their Superdome Flex and Superdome Flex 280 Servers.

Microchip Advisory - Microchip published an advisory that discusses the Blue's Clues vulnerabilities.

NOTE: Watch Blue’s Clues (sorry, I could not help myself), cute name and everything. It looks like this will be a major issue for Bluetooth enabled devices, particularly medical devices.

Motorola Advisory - Motorola published an advisory discussing the Fortinet buffer overflow vulnerability.

TandD Advisory - TandD published an end of support notice for products operating on Windows 7 and Windows 8 platforms.

Western Digital Advisory - Western Digital published an advisory describing an information disclosure vulnerability in their My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.

Vendor Updates

Siemens Update - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-349-14) for the new information.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-f5b - subscription required.

Saturday, June 25, 2022

Review – Public ICS Disclosure – Week of 6-18-22

This week we have 27 vendor disclosures from ABB, Aruba Networks, Bosch, Broadcom (9), CODESYS, Hikvision, HPE (2), Moxa, Phoenix Contact, QNAP, Tanzu and WatchGuard (7). We also have six vendor updates from CODESYS (2), HPE (3), and Schneider. Finally, we have two exploits for products from Siemens and SolarView.

ABB Advisory - ABB published an advisory that describes an insufficient file access control vulnerability in their Relion REX640 protection and control relays.

Aruba Advisory - Aruba published an advisory that discusses the TLStorm2.0 vulnerabilities.

Bosch Advisory - Bosch published an advisory that describes 95 vulnerabilities in their PRA-ES8P2S Ethernet-Switch.

Broadcom Advisory #1 - Broadcom published an advisory that discusses a Java compromise vulnerability in their SANnav  products.

Broadcom Advisory #2 - Broadcom published an advisory that describes an insecure password storage vulnerability in the SANnav products.

Broadcom Advisory #3 - Broadcom published an advisory that discusses a Java compromise vulnerability in their SANnav  products.

Broadcom Advisory #4 - Broadcom published an advisory that discusses a Java compromise vulnerability in their SANnav  products.

Broadcom Advisory #5 - Broadcom published an advisory that describes an insecure password storage vulnerability in their SANnav products.

Broadcom Advisory #6 - Broadcom published an advisory that discusses an off-by-one error vulnerability in their SANnav  products.

Broadcom Advisory #7 - Broadcom published an advisory that discusses an observable discrepancy vulnerability in their SANnav  products.

Broadcom Advisory #8 - Broadcom published an advisory that describes a use of static key ciphers vulnerability in in their SANnav products.

Broadcom Advisory #9 - Broadcom published an advisory that discusses a Java compromise vulnerability in their SANnav  products.

CODESYS Advisory - CODESYS published an advisory that describes nine vulnerabilities in their V2 runtime systems.

Hikvision Advisory - Hikvision published an advisory that describes two insufficient input validation vulnerabilities in their Hybrid SAN/Cluster Storage products.

HPE Advisory #1 - HPE published an advisory that describes a disclosure of sensitive information vulnerability in their NonStop DSM/SCM products.

HPE Advisory #2 - HPE published an advisory that describes a weak key exchange vulnerability in their StoreOnce Software.

Moxa Advisory - Moxa published an advisory that discusses an expression language injection vulnerability in the third-party Apache Struts product.

Phoenix Contact Advisory - Phoenix Contact republished an advisory that describes a missing authentication for critical function vulnerability with a known exploit in their ProConOS/ProConOS eCLR PLC runtime system.

QNAP Advisory - QNAP published an advisory that discusses an out-of-bounds write vulnerability with a known exploit in their NAS product.

Tanzu Advisory - Tanzu published an advisory that describes an expression injection vulnerability in their Spring Data MongoDB application.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes an arbitrary file read vulnerability in their Firebox and XTM appliances.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes a cross-site scripting vulnerability in their Fireware OS.

Watch Guard Advisory #3 - WatchGuard published an advisory that describes a buffer overflow vulnerability in their Fireware OS.

WatchGuard Advisory #4 - WatchGuard published an advisory that describes a stack-based buffer overflow vulnerability in their Fireware OS.

WatchGuard Advisory #5 - WatchGuard published an advisory that describes an information disclosure vulnerability in their Fireware OS.

WatchGuard Advisory #6 - WatchGuard published an advisory that describes a privilege escalation vulnerability in their Fireware OS.

WatchGuard Advisory #7 - WatchGuard published an advisory that describes an argument injection vulnerability in their Fireware OS.

CODESYS Update #1 - CODESYS published an update for their V2 product advisory that was originally published on June 9th, 2022.

CODESYS Update #2 - CODESYS published an update for their Control V2 product advisory that was originally published on June 9th, 2022.

HPE Update #1 - HPE published an update for their ProLiant BL/DL/ML/XL/MicroServer advisory that was originally published on May 10th, 2022 and most recently updated on May 31st, 2022.

HPE Update #2 - HPE published an update for their Superdome Flex advisory that was originally published on June 14th, 2022.

HPE Update #3 - HPE published an update for their Superdome Flex Server advisory that originally published on June 7th, 2022.

Schneider Update - Schneider published an update for their IGSS advisory that was originally published on June 14th, 2022.

Siemens Exploit - Steffen Robertz published an exploit for a cross-site scripting vulnerability in the Siemens SINEMA Remote Connect product.

 

For more details on these disclosures, including links to researcher reports, 3rd party advisories, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-6-18 - subscription required.

 
/* Use this with templates/template-twocol.html */