Showing posts with label Keysight. Show all posts
Showing posts with label Keysight. Show all posts

Tuesday, September 30, 2025

Review – 7 Advisories and 3 Updates Published – 9-30-25

Today CISA’s NCCIC-ICS published seven control system security advisories for products from LG Innotek, National Instruments, OpenPLC, Festo (3) and MegaSys Enterprises. The also published updates for advisories for products from Rockwell Automation, HEIDENHHAIN, and Keysight.

Advisories

LG Advisory - This advisory describes an authentication bypass by alternate path or channel vulnerability in the LG Innotek LND7210 and LNV7210R cameras.

National Instruments Advisory - This advisory describes two vulnerabilities in the NI Circuit Design Suite.

OpenPLC Advisory - This advisory describe a reliance on undefined, unspecified, or implementation defined behavior vulnerability in the OpenPLC_V3 product.

Festo Advisory #1 - This advisory discusses 29 vulnerabilities in the Festo Controller CECC-S,-LK,-D Family Firmware.

Festo Advisory #2 - This advisory describes an improper privilege management vulnerability in the Festo CPX-CEC-C1 and CPX-CMXX hardware control blocks.

Festo Advisory #3 - This advisory discusses four vulnerabilities in the Festo SBRD-Q/SBOC-Q/SBOI-Q series products.

NOTE: I briefly discussed these vulnerabilities on October 2nd, 2021.

MegaSys Advisory - This advisory describes an OS command injection vulnerability in the MegaSys Telenium Online Web Application.

Updates

Rockwell Update - This update provides additional information on the FLEX 5000 I/O advisory that was originally published on August 14th, 2025.

NOTE: I described the problem with the incorrect CVE numbers on August 14th, 2025.

HEIDENHAIN Update - This update provides additional information on the Controller TNC advisory that was originally published on October 25th, 2022.

Keysight Update - This update provides additional information on the Ixia Vision advisory that was originally published on March 4th, 2025.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-3-updates-published-e07 - subscription required.

Tuesday, March 4, 2025

Review – 8 Advisories Published – 3-4 -25

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Edimax, GMOD, Delta Electronics, Hitachi Energy (3), Keysight, and Carrier.

Advisories

Edimax Advisory - This advisory describes an OS command injection vulnerability in the Edimax IC-7100 IP Camera.

GMOD Advisory - This advisory describes four vulnerabilities in the GMOD Apollo genome annotation editor.

Delta Advisory - This advisory describes a heap-based buffer overflow vulnerability in the Delta CNCSoft-G2 human-machine interface.

Hitachi Energy Advisory #1 - This advisory describes an improper validation of certificate with host mismatch vulnerability in the Hitachi Energy XMC20, ECST, and UNEM products.

Hitachi Energy Advisory #2 - This advisory describes relative path traversal vulnerability in the Hitachi Energy XMC20 multiservice communication platform.

Hitachi Energy Advisory #3 - This advisory discusses an uncontrolled search path element vulnerability in the Hitachi Energy MACH PS700 control system.

Keysight Advisory - This advisory describes four vulnerabilities in the Keysight Ixia Vision Product Family.

 

For more information on these advisories, including links to earlier discussions about some of these reported advisories and an apparently duplicate CISA advisory, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-3-4-25 - subscription required.

Tuesday, November 21, 2023

Review – 2 Advisories and 3 Updates Published – 11-21-23

Today, CISA’s NCCIC-ICS published two control system security updates for products from Fuji Electric and WAGO. They also updated advisories for products from Rockwell Automation, Keysight, and Mitsubishi Electric.

Advisories

Fuji Advisory - This advisory describes three vulnerabilities in the Fuji Tellus Lite V-Simulator.

WAGO Advisory - This advisory that describes an externally controlled reference to a resources in another sphere vulnerability in the WAGO PFC200 Series products.

WAGO Advisory - This advisory that describes an externally controlled reference to a resources in another sphere vulnerability in the WAGO PFC200 Series products.

Updates                                                                                      

Rockwell Update - This update provides additional information on the Stratix 5800 and Stratix 5200 advisory that was originally published on October 24th, 2023.

Keysight Update - This update provides additional information on the N8844A Data Analytics advisory that was originally published on April 25th, 2023.

Mitsubishi Update - This update provides additional information on the CNC Series advisory that was originally published on July 27th, 2023 and most recently updated on October 31st, 2023.

 

For more details about these advisories, including notes about the vendor advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-3-updates-published-132 - subscription required.

Tuesday, April 25, 2023

Review – 2 Advisories Published – 4-25-23

Today, CISA’s NCCIC-ICS published two control system security advisories for products from SCADA-LTS and Keysight.

Advisories

SCADAS-LTS Advisory - This advisory discusses a cross-site scripting vulnerability in the SCADA-LTS open-source HMI.

Keysight Advisory - This advisory describes a deserialization of untrusted data vulnerabilities in the Keysight N8844A Data Analytics Web Service.

 

For more details about these advisories, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-4-25-23 - subscription required.

Tuesday, March 21, 2023

Review – 7 Advisories and 1 Update Published – 3-21-23

Today, CISA’s NCCIC-ICS published seven control system security advisories for products from Siemens (3), Rockwell Automation, VISAM, Delta Electronics, Keysight Technologies, and Hitachi Energy.

Advisories

SCALANCE Advisory - This advisory discusses 17 vulnerabilities in the Siemens SCALANCE W-700 product line.

RADIUS Advisory - This advisory discusses an infinite loop vulnerability in the Siemens RADIUS client of SIPROTEC 5 devices.

RUGGEDCOM Advisory - This advisory discusses seven TOCTOU race condition vulnerabilities in the Siemens RUGGEDCOM APE1808 Product Family.

Rockwell Advisory - This advisory describes three vulnerabilities in the Rockwell ThinManager ThinServer.

VISAM Advisory - This advisory describes seven improper restriction of XML entity reference vulnerabilities in the VISAM VBASE Automation Base. 

Delta Advisory - This advisory describes 13 vulnerabilities in the Delta InfraSuite Device Master.

Keysight Advisory - This advisory describes a deserialization of untrusted data vulnerability in the Keysight N6854A Geolocation Sever.

Updates

Hitachi Energy Update - This update provides additional information on an advisory that was originally published on December 9th, 2021.

 

For more details about these advisories, including links to 3rd party advisories and exploits, as well as a brief summary of changes made in the update, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/7-advisories-and-1-update-published-541 - subscription required.

Saturday, November 5, 2022

Review – Public ICS Disclosure – Week of 10-29-22

This week we have twelve vendor disclosures about the recent OpenSSL vulnerabilities from Aruba Networks, Broadcom, Keysight, Milestone, Moxa, Palo Alto Networks, Roche, Rockwell Automation, Software Toolbox, Watchguard, and Wind River.   We also have twelve other vendor disclosures from Belden, Hitachi, Insyde (6), Sick, and Tanzu (3). There are six vendor updates for products from CODESYS. Finally, we have two exploits for products from FLIR, and Veeder-Root.

OpenSSL Vulnerabilities Disclosures

Aruba reports that none of their products are affected by the vulnerabilities.

Broadcom provides a list of unaffected products.

Dell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Keysight reports that none of their products are affected by the vulnerabilities.

Milestone reports limited impact in their XProtect VMS 2022 R3. An update is pending.

Moxa reports that none of their products are affected by the vulnerabilities.

Palo Alto Networks reports that earlier versions of Cortex XDR Broker VM contain the affected OpenSSL version but are not affected by the vulnerabilities. Other products are not affected.

Roche reports that none of their products are affected by the vulnerabilities.

Rockwell reports that they are reviewing their products to see which may be affected by the vulnerabilities.

Software Toolbox reports that none of their products are affected by the vulnerabilities.

Watchguard provides a list of unaffected products.

Wind River provides a list of affected products. Fixes are pending.

Other Vendor Disclosures

Belden Advisory - Belden published an advisory that describes a command insertion vulnerability in their (Hirschmann) Industrial HiVision product.

Hitachi Advisory - Hitachi published an advisory that discusses 60 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities

Insyde Advisory #1 - Insyde published an advisory that discusses an observable discrepancy vulnerability in their InsydeH2O product.

Insyde Advisory #2 - Insyde published an advisory that discusses two vulnerabilities in their InsydeH2O product.

Insyde Advisory #3 - Insyde published an advisory that discusses an out-of-bounds read vulnerability in their InsydeH2O product.

Insyde Advisory #4 - Insyde published an advisory that describes a stack-based buffer overflow vulnerability in their InsydeH2O product.

Insyde Advisory #5 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Insyde Advisory #6 - Insyde published an advisory that describes a stack-based buffer overflow in their InsydeH2O product.

Sick Advisory - Sick reports a denial of service vulnerability in their FlexiCompact product.

NOTE: The Sick PSIRT web page continues to have problems with inoperable links.

Tanzu Advisory #1 - Tanzu published an advisory that describes a privilege escalation vulnerability in their pring-security-oauth2-client.

Tanzu Advisory #2 - Tanzu published an advisory that describes an authorization bypass vulnerability in their Spring Security product.

Tanzu Advisory #3 - Tanzu published an advisory that describes a remote code execution vulnerability in their Spring Tools 4 for Eclipse product.

CODESYS Update #1 - CODESYS published an update for their CODESYS communication server advisory that was originally published on May 19th, and most recently updated on October 6th, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #3 - CODESYS published an update for their a CODESYS communication server advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #4 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on June 30th 2022.

CODESYS Update #5 - CODESYS published an update for their V3 products using the CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on June 30th, 2022.

CODESYS Update #6 - CODESYS published an update for their Control V3 configuration file advisory that was originally published on March 24th, 2022, and most recently updated on October 6th, 2022.

Exploits

FLIR Exploit - Samy Younsi published a Metasploit module for a command injection vulnerability in the FLIR AX8 infrared monitoring camera.

Veeder-Root Exploit - Rose Security published an exploit for a remote configuration disclosure vulnerability in the Veeder-Rood (and probably other vendor) automated tank gauges.

 

For more details about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-c49 - subscription required.

 

Saturday, August 13, 2022

Review – Public ICS Disclosures – Week of 8-6-22 – Part 1

This Saturday after the second Tuesday we have a large slate of disclosures to look at. For Part 1, we have 24 vendor disclosures from Auma, Fujitsu, HP (7), HPE (6), Keysight Technologies, Palo Alto Networks (2), PcVue, Schneider (4), and Sick.

Auma Advisory - CERT-VDE published an advisory that discusses 73 vulnerabilities in the Auma SIMA Master Station.

Fujitsu Advisory - Fujitsu published an advisory that discusses three vulnerabilities in a number of Fujitsu products.

HP Advisory #1 - HP published an advisory that discusses 14 vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #2 - HP published an advisory that discusses an improper restriction of XML external entity reference vulnerability in a wide variety of their PCs, notebooks and workstations.

HP Advisory #3 - HP published an advisory that discusses an improper restriction of XML external entity reference vulnerability (with a known exploit) in a wide variety of their PCs, notebooks and workstations.

HP Advisory #4 - HP published an advisory that discusses four vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #5 - HP published an advisory that discusses three vulnerabilities in in a wide variety of their PCs, notebooks and workstations.

HP Advisory #6 - HP published an advisory that discusses four vulnerabilities in a wide variety of their PCs, notebooks and workstations.

HP Advisory #7 - HP published an advisory that discusses an information disclosure vulnerability in a wide variety of their PCs, notebooks and workstations.

HPE Advisory #1 - HPE published an advisory that discusses a privilege escalation vulnerability in their HPE ProLiant DL Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their ProLiant DL/ML Servers.

HPE Advisory #3 - HPE published an advisory that discusses an information disclosure vulnerability in their ProLiant DX Servers.

HPE Advisory #4 - HPE published an advisory that discusses a privilege escalation vulnerability in their Synergy Servers.

HPE Advisory #5 - HPE published an advisory that discusses an information disclosure vulnerability in their Synergy Servers.

HPE Advisory #6 - HPE published an advisory that discusses a privilege escalation vulnerability ProLiant DX Servers.

Keysight Advisory - INCIBE-CERT published an advisory that describes two vulnerabilities in the Keysight Sensor Management Server.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a reduced effectiveness of their Cortex XDR Agent anti-ransomware endpoint protection module.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a reflected amplification DOS vulnerability in their PAN-OS.

PcVue Advisory - PcVue published an advisory that describes a clear-text storage of sensitive information in their PcVue OAuth web service.

Schneider Advisory #1 - Schneider published an advisory that describes a weak password recovery vulnerability in their EcoStruxure™ Control Expert , EcoStruxure™ Process Expert, Modicon M580 and M340 products.

Schneider Advisory #2 - Schneider published an advisory that describes an integer underflow vulnerability in their Modicon PAC Controllers.

Schneider Advisory #3 - Schneider published an advisory that describes an improper restriction of operations within the bounds of a memory buffer.

Schneider Advisory #4 - Schneider published an advisory that describes an information disclosure vulnerability in their Modicon PAC Controllers.

Sick Advisory - Sick published an advisory that discusses an infinite loop vulnerability in their SIM products. This is a third-party (OpenSSL).

 

For more details on these advisories, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-e7f - subscription required.

Thursday, May 26, 2022

Review – 2 Advisories Published – 5-26-22

Today, CISA’s NCCIC-ICS published two control system security advisories for products from Horner Automation and Keysight Technologies.

Horner Advisory - This advisory describes four vulnerabilities in the Horner Cscape PLC management software.

Keysight Advisory - This advisory describes two vulnerabilities in the Keysight N6854A Geolocation server and N6841A RF Sensor software.

 

For more details on these advisories, including a new ‘Down the Rabbit Hole’ feature looking at the cybersecurity support on the Keysight website, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-5-26-22 - subscription required.

 

 
/* Use this with templates/template-twocol.html */