Showing posts with label Jumo. Show all posts
Showing posts with label Jumo. Show all posts

Sunday, May 31, 2026

Review - Public ICS Disclosures – Week of 5-23-26 – Part 2

For Part 2 we have 12 additional vendor disclosures from Hitachi Energy (3), JUMO, MB connect (2), METTLER TOLEDO, Moxa, NI, Phoenix Contact, and QNAP (2). 

Advisories  

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their ITT600 Explorer product. 

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes a heap-based buffer overflow vulnerability in their MACH HiDraw product. 

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that describes four vulnerabilities in their RTU500 product. 

JUMO Advisory - CERT-VDE published an advisory that discusses an improper input validation vulnerability (with publicly available exploit) in multiple JUMO products. 

MB connect Advisory #1 MB connect published an advisory that describes an SQL injection vulnerability in their mbCONNECT24 and mymbCONNECT24 products. 

MB connect Advisory #2 MB connect published an advisory that describes two vulnerabilities in in their mbNET/mbNET.rokey and mbNET.mini products. 

METTLER TOLEDO Advisory - CERT-VDE published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their EVA Karl Fischer titrator software. 

Moxa Advisory - Moxa published an advisory that discusses the Copy Fail and Dirty Frag vulnerabilities. 

NI Advisory NI published an advisory that describes a missing authentication for critical function vulnerability in their SystemLink Enterprise product. 

Phoenix Contact Advisory Phoenix Contact published an advisory that describes two vulnerabilities in their PLCnext firmware. 

QNAP Advisory #1 QNAP published an advisory that discusses the Dirty Frag vulnerabilities. 

QNAP Advisory #2 - QNAP published an advisory that discusses the Copy Fail vulnerability. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-f0a - subscription required. 

Saturday, November 15, 2025

Review – Public ICS Disclosures – Week of 11-8-25 – Part 1

A moderately busy Cyber Week. For Part 1 this week we have 18 vendor disclosures from GE Vernova (4), Hitachi (4), HP (4), HPE (3), Jumo, and Palo Alto Networks (2).

Advisories

GE Vernova Advisory #1 - GE Published an advisory that discusses three vulnerabilities in the Gas Power Controls products.

GE Vernova Advisory #2 - GE published an advisory that discusses an uncaught exception vulnerability for unlisted products using AVEVA PI Server and PI Data Archive.

GE Vernova Advisory #3 - GE published an advisory that describes a path traversal vulnerability in their Smallworld Master File Server (SWMFS) Software.

GE Vernova Advisory #4 - GE published an advisory that describes an improper authentication vulnerability in their Smallworld Master File Server (SWMFS) Software.

Hitachi Advisory #1 - Hitachi published an advisory that discusses 44 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities.

Hitachi Advisory #2 - Hitachi published an advisory that discusses a covert timing channel vulnerability in their JP1 products.

Hitachi Advisory #3 - Hitachi published an advisory that discusses two vulnerabilities in their JP1 products.

Hitachi Advisory #4 - Hitachi published an advisory that discusses three vulnerabilities in their Cosminexus Developer's Kit for Java(TM) and Hitachi Developer's Kit for Java.

HP Advisory #1 - HP published an advisory that describes two exposure of sensitive information vulnerabilities in their LaserJet Pro Printers.

HP Advisory #2 - HP published an advisory that discusses three vulnerabilities in multiple HP product lines.

HP Advisory  #3 - HP published an advisory that discusses six vulnerabilities in multiple HP product lines.

HP Advisory #4 - HP published an advisory that discusses three vulnerabilities in multiple HP product lines.

HPE Advisory #1 - HPE published an advisory that discusses a stale translation lookaside buffer (TLB) entry vulnerability in their HPE SimpliVity servers.

HPE Advisory #2 - HPE published an advisory that discusses an active debug code vulnerability in their ProLiant DL, and Synergy Servers.

HPE Advisory #3 - HPE published an advisory that discusses a stale translation lookaside buffer (TLB) entry vulnerability in their ProLiant DL/XL servers.

Jumo Advisory - CERT VDE published an advisory that describes the use of a cryptographically weak PRNG vulnerability in the Jumo variTRON password generation algorithm.

Palo Alto Network Advisory # 1 - PAN published an advisory that discusses 23 vulnerabilities in their Prisma Browser.

Palo Alto Network Advisory #2 - PAN published an advisory that describes an improper check for unusual or exceptional conditions vulnerability in their PAN-OS and Prisma Access products.


For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-66f  - subscription required.
 
/* Use this with templates/template-twocol.html */