Showing posts with label Hitachi. Show all posts
Showing posts with label Hitachi. Show all posts

Saturday, June 13, 2026

Review – Public ICS Disclosures – 6-6-26 – Part 1

This has been a relatively busy disclosure week. For Part 1 we have 14 vendor disclosures from B&R (2), FortiGuard (2), Hitachi (2), HP (3), HPE (4), and Mitsubishi. 

Advisories  

B&R Advisory #1 - B&R published an advisory that discusses five vulnerabilities (four with publicly available exploits) in multiple Linux based B&R products. 

B&R Advisory #2 - B&R published an advisory that discusses a race condition within a thread vulnerability in multiple B&R products. 

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an internal asset exposed to unsafe debug access level or state vulnerability in their FortiOS and FortiProxy products. 

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiSandbox product. 

Hitachi Advisory #1 - Hitachi published an advisory that describes an iSCSI port vulnerability in multiple Hitachi products. 

Hitachi Advisory #2 - Hitachi published an advisory that discusses an improper neutralization of escape, meta or control sequences vulnerability in their Cosminexus HTTP Server and Hitachi Web Server. 

HP Advisory #1 - HP published an advisory that discusses nine vulnerabilities in multiple HP product lines. 

HP Advisory #2 - HP published an advisory that discusses an improper isolation of shared resources on system-on-a-chip vulnerability in multiple HP product lines. 

HP Advisory #3 - HP published an advisory that discusses an improper handling of insufficient entropy in TRNG vulnerability in multiple HP product lines. 

HPE Advisory #1 - HPE published an advisory that discusses an improper access control for register interface vulnerability in their ProLiant AMD Servers. 

HPE Advisory #2 - HPE published an advisory that discusses a race condition vulnerability in their RL300 Server. 

HPE Advisory #3 - HPE published an advisory that discusses the FunkyChunks vulnerability. HPE provides a list of affected products. 

HPE Advisory #4 - HPE published an advisory that discusses a heap-based buffer overflow vulnerability in their Aruba Networking Products. 

Mitsubishi Advisory - Mitsubishi published an advisory that describes a use of hard-coded credentials vulnerability in multiple home appliance products. 


For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis https://patrickcoyle.substack.com/p/public-ics-disclosures-6-6-26-part - subscription required. 

Sunday, May 31, 2026

Review - Public ICS Disclosures – Week of 5-23-26 – Part 2

For Part 2 we have 12 additional vendor disclosures from Hitachi Energy (3), JUMO, MB connect (2), METTLER TOLEDO, Moxa, NI, Phoenix Contact, and QNAP (2). 

Advisories  

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their ITT600 Explorer product. 

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes a heap-based buffer overflow vulnerability in their MACH HiDraw product. 

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that describes four vulnerabilities in their RTU500 product. 

JUMO Advisory - CERT-VDE published an advisory that discusses an improper input validation vulnerability (with publicly available exploit) in multiple JUMO products. 

MB connect Advisory #1 MB connect published an advisory that describes an SQL injection vulnerability in their mbCONNECT24 and mymbCONNECT24 products. 

MB connect Advisory #2 MB connect published an advisory that describes two vulnerabilities in in their mbNET/mbNET.rokey and mbNET.mini products. 

METTLER TOLEDO Advisory - CERT-VDE published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their EVA Karl Fischer titrator software. 

Moxa Advisory - Moxa published an advisory that discusses the Copy Fail and Dirty Frag vulnerabilities. 

NI Advisory NI published an advisory that describes a missing authentication for critical function vulnerability in their SystemLink Enterprise product. 

Phoenix Contact Advisory Phoenix Contact published an advisory that describes two vulnerabilities in their PLCnext firmware. 

QNAP Advisory #1 QNAP published an advisory that discusses the Dirty Frag vulnerabilities. 

QNAP Advisory #2 - QNAP published an advisory that discusses the Copy Fail vulnerability. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-f0a - subscription required. 

 
/* Use this with templates/template-twocol.html */