Showing posts with label ICS Disclosure. Show all posts
Showing posts with label ICS Disclosure. Show all posts

Saturday, December 23, 2023

Review – Public ICS Disclosures – Week of 9-16-23

This week we have 18 vendor disclosures from Broadcom (3), Eaton (2), GE Gas Power, Hitachi, Hitachi Energy (2), Honeywell, HPE (4), Mitsubishi, Moxa, and SEL (2). There are five vendor updates from Cisco (2) and Hitachi Energy (3). Finally, we have 29 researcher reports for vulnerabilities in products from Honeywell (7), Inductive Automation, and Voltronic Power (21).

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses a path traversal vulnerability in their Brocade Fabric OS.

Broadcom Advisory #2 - Broadcom published an advisory that discusses a path traversal vulnerability in their Brocade Fabric OS.

Broadcom Advisory #3 - Broadcom published an advisory that discusses a missing authentication vulnerability in their Brocade Fabric OS.

Eaton Advisory #1 - Eaton Advisories - Eaton published an advisory that describes an access control vulnerability in their User Management System.

Eaton Advisory #2 - Eaton published an advisory that discusses a deserialization of untrusted data vulnerability in multiple Eaton products that is listed in the CISA Known Exploited Vulnerability Catalog.

GE Gas Power Advisory - GE Published an advisory that discusses an authentication bypass vulnerability in the  Triangle Microworks SCADA Data Gateway.

Hitachi Advisory - Hitachi published an advisory that discusses two vulnerabilities in the JP1/VERITAS product.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes an improper input validation vulnerability in their RTU500 series products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes an improper certificate validation vulnerability in their RTU500 scripting interface.

Honeywell Support Notice - Honeywell published a support notice for their Vindicator line of access control systems. Honeywell notes that their systems using Windows 7 and Windows XP operating systems will receive only limited support.

HPE Advisory #1 - HPE published an advisory that discusses three vulnerabilities in their Unified OSS Console.

HPE Advisory #2 - HPE published an advisory that describes a cross-site scripting vulnerability in their Unified OSS Console.

HPE Advisory #3 - HPE published an advisory that discusses a code corruption vulnerability in their IceWall Gen11 certd module.

HPE Advisory #4 - HPE published an advisory that describes an authentication bypass vulnerability in their Integrated Lights-Out 5 and 6 products.

Mitsubishi Advisory - Mitsubishi published an advisory that discusses three vulnerabilities in multiple FA products.

Moxa Advisory - Moxa published an advisory that describes two vulnerabilities in their ioLogik E1200 Series Web Server.

SEL Advisory - SEL published two software revisions notices that included fixes for cybersecurity vulnerabilities.

Updates

Cisco Update #1 - Cisco published an update for their HTTP/2 Rapid Reset Attack advisory that was originally published on October 16th, 2023 and most recently updated on December 5th, 2023.

Cisco Update #2 - Cisco published an update for their Apache Struts Vulnerability advisory that was originally published on December 12th, 2023 and most recently updated on December 15th, 2023.

Hitachi Energy Update #1 - Hitachi Energy published an update for their AFS65x, AFS67x, AFR67x and AFF66x series products advisory that was originally published on September 26th, 2023.

Hitachi Energy Update #2 - Hitachi Energy published an update for their AFF66x products advisory that was originally published on July 25th, 2023.

Hitachi Energy Update #3 - Hitachi Energy published an update for their Apache ActiveMQ advisory that was originally published on November 14th, 2023.

Researcher Reports

Honeywell Reports - ZDI published 7 advisories for individual vulnerabilities in the Honeywell Saia PG5 Controls Suite.

Inductive Automation Report - ZDI published a report that describes a deserialization of untrusted data vulnerability in the Inductive Automation Ignition product.

Voltronic Reports - The Zero Day Initiative published 21 advisories for individual vulnerabilities in the Voltronic Power ViewPower Pro.

 

For more details about these disclosures, including links to researcher reports and 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-552 - subscription required.

Sunday, December 18, 2022

Review – Public ICS Disclosures – Week of 12-10-22 – Part 2

For part 2 we have twelve additional vendor disclosures from Rockwell Automation (3), Schneider (2), Sick, VMware (4), Weidmueller, and Wiesemann & Theis. We also have seven vender updates from CODESYS (3), Dell, HPE, Mitsubishi, and Omron. Finally, we have one researcher report for products from VMware.

Vendor Disclosures

Rockwell Advisory #1 - Rockwell published an advisory that describes a denial of service vulnerability in their MicroLogix 1100 & 1400 Product Web Server application.

Rockwell Advisory #2 - Rockwell published an advisory that describes a cross-site scripting vulnerability in their MicroLogix 1100 & 1400 Web Server application.

Rockwell Advisory #3 - Rockwell published an advisory that describes a denial of service vulnerability in their GuardLogix and ControlLogix controllers.

Schneider Advisory #1 - Schneider published an advisory that describes an improper authorization vulnerability in their EcoStruxure Power Commission.

Schneider Advisory #2 - Schneider published an advisory that discusses an out-of-bounds write vulnerability in their Saitel DR RTU (Remote Terminal Unit).

Sick Advisory - Sick published an advisory that describes four vulnerabilities in the n SICK RFU6xx RADIO FREQUEN. SENSOR 1.

VMware Advisory #1 - VMware published an advisory that describes two vulnerabilities in their vRealize Network Insight (vRNI) product.

VMware Advisory #2 - VMware published an advisory that describes two vulnerabilities in their Workspace ONE Access and Identity Manager.

VMware Advisory #3 - VMware published an advisory that describes a heap-based write vulnerability in their ESXi, Workstation, and Fusion products.

VMware Advisory #4 - VMware published an advisory that describes two vulnerabilities in their vRealize Operations product.

Weidmueller Advisory - CERT-VDE published an advisory that describes a JavaScript injection vulnerability in the Weidmueller XML editing system SCHEMA ST4 online help.

Wiesemann & Theis Advisory - CERT-VDE published an advisory that describes an authentication bypass by spoofing vulnerability in multiple Wiesemann & Theis products.

Vendor Updates

CODESYS Update #1 - CODESYS published an update for their Control V3 communication server advisory that was originally published on November 22nd, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 boot application advisory that was originally published on November 23rd, 2022.

CODESYS Update #3 - CODESYS published an update for their V2 password transport advisory that was originally published on June 9th, 2022 and most recently updated on October 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V2 and V3 runtime systems advisory that was originally published on March 22nd, 2018 and most recently updated on July 9th, 2018.

Dell Update - Dell published an update for their Log4Shell advisory.

HPE Update - HPE published an update for their NonStop advisory that was originally published on July 18th, 2022.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64TM and MC Works64 advisory that that was originally published on July 19th, 2022 and most recently updated on September 30th, 2022.

Omron Update - JP-CERT published an update for their OMRON CX-Programmer advisory that was originally published on November 25th, 2022.

Researcher Report

VMware Report - CISCO Talos published a report describing a denial-of-service vulnerability in the VMware vCenter Server Content Library.

 

For additional information on these disclosures, including links to third-party advisories, exploits, and brief summary of changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-720 - subscription required.


 
/* Use this with templates/template-twocol.html */