Showing posts with label Luxion. Show all posts
Showing posts with label Luxion. Show all posts

Saturday, June 8, 2024

Review – Public ICS Disclosures – Week of 6-1-24

This week we have nine vendor disclosures from ABB (2), Checkpoint, HPE (3), IFM, WatchGuard, and Zyxel. There are also eleven updates from Broadcom (2), CODESYS (2), and HPE (7). Finally, we have three researcher reports of vulnerabilities in products from FortiGuard, and Luxion (2).

Advisories

ABB Advisory #1 - ABB published an advisory that describes a cross-site scripting vulnerability in their WebPro SNMP card.

ABB Advisory #2 - ABB published an advisory that describes two vulnerabilities in their KNX Secure Devices.

Checkpoint Advisory - Checkpoint published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability that is listed on the CISA Known Exploited Vulnerability (KEV) catalog.

HPE Advisory #1 - HPE published an advisory that describes an authentication bypass vulnerability in their Cray Parallel Application Launch Service (PALS).

HPE Advisory #2 - HPE published an advisory that discusses two improper input validation vulnerabilities in their StoreEasy Servers.

HPE Advisory #3 - HPE published an advisory that discusses two improper input validation vulnerabilities in their ProLiant DL/ML/Edgeline/Synergy and Alletra Servers.

IFM Advisory - CERT-VDE published an advisory that describes a weak password recovery mechanism for forgotten password vulnerability in the IFM moneo software.

SEL Advisory - SEL announced that the latest versions of their SEL-5030 acSELerator QuickSet Software contains security enhancements.

WatchGuard Advisory - WatchGuard published an advisory that discusses the TunnelVision vulnerability.

Zyxel Advisory - Zyxel published an advisory that describes five vulnerabilities in their NAS products.

Updates

Broadcom Update #1 - Broadcom published an update for their Incident Response Team Contact Information advisory that was originally published on February 7th, 2023.

Broadcom Update #2 - Broadcom published an update for their Brocade Fabric OS advisory that was originally published on April 4th, 2024, and most recently updated on May 5th, 2024.

CODESYS Update #1 - CODESYS published an update for their OPC UA Stack advisory that was originally published on May 22nd, 2024.

CODESYS Update #2 - CODESYS published an update for their Gateway for Windows advisory that was originally published on May 22nd, 2024.

HPE Update #1 - HPE published an update for their Aruba ArubaOS advisory that was originally published on April 30th, 2024 and most recently updated on May 21st, 2024.

HPE Update #2 - HPE published an update for their Aruba Networking ClearPass Policy Manager advisory that was originally published on February 27th, 2024.

HPE Update #3 - HPE published an update for their Aruba Access Points advisory that was originally published on May 14th, 2024.

HPE Update #4 - HPE published an update for their Aruba ArubaOS advisory that was originally published on March 5th, 2024.

HPE Update #5 - HPE published an update for their ArubaOS-CX Switches advisory that was originally published on May 8th, 2024 and most recently updated on May 28th, 2024.

HPE Update #6 - HPE published an update for their ArubaOS-Switch Switches advisory that was originally published on March 26th, 2024.

HPE Update #7 - HPE published an update for their ProLiant DL/DX/ML/SY/RL/XL/Edgeline Servers advisory that was originally published on April 2nd, 2024 and most recently updated on May 14th, 2024.

Researcher Reports

FortiGuard Report - Horizion3 published a report discusses the SQL injection vulnerability (listed in the CISA KEV catalog) in the FortiClient EMS v7.2.X products.

Luxion Reports - The Zero Day Initiative published two reports discussing vulnerabilities in the Luxion KeyShot product.

 

For more information on these disclosures, including links to third-party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-8cc - subscription required.

Saturday, November 18, 2023

Review – Public ICS Disclosures – Week of 11-11-23 – Part 1

A busy Cyber Tuesday week. For Part 1 we have 26 vendor disclosures from Aruba Networks, Blackberry, FortiGuard (3), Hitachi Energy, HPE (10), ICSSolution, Luxion, Philips, SEL (2), and Splunk (6).

Advisories

Aruba Advisory - Aruba published an advisory that describes 14 vulnerabilities in their Access Points products.

Blackberry Advisory - Blackberry published an advisory that describes an improper input validation vulnerability in their QNX Networking Stack.

FortiGuard Advisory #1 - FortiGuard published an advisory that discusses two vulnerabilities in their FortiOS product.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an improper integrity check value vulnerability in their FortiOS and FortiProxy VM products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a NULL pointer dereference vulnerability in their FortiOS and FortiProxy products.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses a deserialization of untrusted data vulnerability that is on the CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

HPE Advisory #1 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their Apollo and XL servers.

HPE Advisory #2 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their ProLiant DX Servers.

HPE Advisory #3 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/XL servers and Cray Supercomputer.

HPE Advisory #4 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their StoreEasy Server.

HPE Advisory #5 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their ProLiant DL/ML and Microservers.

HPE Advisory #6 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/DX/XL Server. These are third-party (AMD) vulnerabilities

HPE Advisory #7 - HPE published an advisory that discusses a sequence of processor instructions that lead to unexpected behavior vulnerability in their Synergy Servers.

HPE Advisory #8 - HPE published an advisory that discusses an improper access control vulnerability in their SimpliVity Servers.

HPE Advisory #9 - HPE published an advisory that discusses the  Downfall Attacks vulnerability in their SimpliVity Servers.

HPE Advisory #10 - HPE published an advisory that discusses an unauthorized error injection vulnerability in their SimpliVity Servers.

ICSSolution Advisory - INCIBE-CERT published an advisory that describes two vulnerabilities in the ICSSolution ICS Business Manager product.

Luxion Advisory - Luxion published an advisory that describes an improper input validation vulnerability in their KeyShot product.

Philips Advisory - Philips published an advisory that discusses the Citrix Bleed vulnerability that is listed in the CISA KEV catalog.

SEL Advisories - SEL published two advisories for unlisted cybersecurity concerns.

Splunk Advisory #1 - Splunk published an advisory that discusses an insufficient verification of data authenticity vulnerability in their Add-on for Amazon Web Services.

Splunk Advisory #2 - Splunk published an advisory that discusses multiple unnamed third-party vulnerabilities in their Add-on for Google Cloud Platform.

Splunk Advisory #3 - Splunk published an advisory that describes a cross-site scripting vulnerability in the Search Page in Splunk Enterprise.

Splunk Advisory #4 - Splunk published an advisory that describes five vulnerabilities in their Enterprise product.

Splunk Advisory #5 - Splunk published an advisory that discusses four vulnerabilities in their Enterprise Cloud product.

Splunk Advisory #6 - Splunk published an advisory that discusses four vulnerabilities in their Universal Forwarder product.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-713 - subscription required.

Sunday, April 16, 2023

Review – Public ICS Disclosures – Week of 4-8-23 – Part 2

For Part 2 we have 30 additional vendor disclosures from FortiGuard (22), Luxion, Schneider (6), and Siemens.

Advisories

FortiGuard Advisory #1 - FortiGuard published an advisory that discusses the DirtyPipe vulnerability in thier FortiProxy & FortiSIEM products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiADC & FortiDDoS & FortiDDoS-F products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiADC product.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes an improper certificate validation vulnerability in their FortiAnalyzer & FortiManager products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes an improper input validation vulnerability in their FortiAnalyzer products.

FortiGuard Advisory #6 - FortiGuard published an advisory that describes a reflected cross-site scripting vulnerability in their FortiAuthenticator product.

FortiGuard Advisory #7 - FortiGuard published an advisory that describes a privilege escalation vulnerability in their FortiClient (Mac).

FortiGuard Advisory #8 - FortiGuard published an advisory that describes an arbitrary file creation vulnerability in their FortiClient (Windows).

FortiGuard Advisory #9 - FortiGuard published an advisory that describes an improper write access vulnerability in their FortiClient (Windows).

FortiGuard Advisory #10 - FortiGuard published an advisory that describes an arbitrary file creation vulnerability in their FortiClientWindows.

FortiGuard Advisory #11 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiGate product.

FortiGuard Advisory #12 - FortiGuard published an advisory that describes an information disclosure vulnerability in their FortiNAC product.

FortiGuard Advisory #13 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiOS & FortiProxy products.

FortiGuard Advisory #14 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiOS & FortiProxy products.

FortiGuard Advisory #15 - FortiGuard published an advisory that describes an open-redirect vulnerability in their FortiOS & FortiProxy products.

FortiGuard Advisory #16 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiPresence.

FortiGuard Advisory #17 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiPresence.

FortiGuard Advisory #18 - FortiGuard published an advisory that describes a server-side template injection vulnerability in their FortiSOAR product.

FortiGuard Advisory #19 - FortiGuard published an advisory that describes an SQL injection vulnerability in their FortiSandbox product.

FortiGuard Advisory #20 - FortiGuard published an advisory that describes an execute unauthorized code or commands vulnerability in their FortiSandbox & FortiDeceptor products.

FortiGuard Advisory #21 - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiWeb & FortiADC products.

FortiGuard Advisory #22 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiWeb product.

Luxion Advisory - Luxion published an advisory that discusses an out-of-bounds write vulnerability in their KeyShot product.

Schneider Advisory #1 - Schneider published an advisory that discusses three vulnerabilities in a number of CODESYS based Schneider products.

Schneider Advisory #2 - Schneider published an advisory that describes an improper input validation vulnerability in their Conext™ Gateway/ InsightHome and InsightFacility.

Schneider Advisory #3 - Schneider published an advisory that describes two vulnerabilities in their EcoStruxure™ Control Expert product.

Schneider Advisory #4 - Schneider published an advisory that describes three vulnerabilities in their Easy UPS Online Monitoring Software.

Schneider Advisory #5 - Schneider published an advisory that describes two improper check for unusual or exceptional conditions vulnerabilities in their Modicon PLCs and PACs.

Schneider Advisory #6 - Schneider published an advisory that describes an uncontrolled search path vulnerability in their Easergy Builder installer.

Siemens Advisory - Siemens published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in their Solid Edge products.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories an exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-fcb - subscription required.

Saturday, July 2, 2022

Review – Public ICS Disclosures – Week of 6-25-22 – Part 1

This has been a relatively busy disclosure week. For Part 1 this week we have 15 vendor disclosures from Belden, Hitachi, Hitachi Energy, Honeywell, HPE (7), Luxion, Omron (2), and Philips.

Belden Advisory - Belden published an advisory that discusses the FragAttacks WiFi vulnerabilities in their ProSoft RadioLinx RLX2.

Hitachi Advisory - Hitachi published an advisory that discusses 30 vulnerabilities in their Virtual Storage Platform products.

Hitachi Energy Advisory - Hitachi Energy published an advisory that describes a stack-based buffer overflow vulnerability in their RTU500 series Product.

Honeywell Notice - Honeywell published a notice of discontinued technical phone support for their PRO2200 Series and to the PROCVT1 communication peripheral.

HPE Advisory #1 - HPE published an advisory that describes a cross-site scripting vulnerability in their FlexNetwork and FlexFabric Switches.

HPE Advisory #2 - HPE published an advisory that describes an SQL injection vulnerability in their IceWall Products Using SSO Certd.

HPE Advisory #3 - HPE published an advisory that discusses eleven vulnerabilities in their HPE SimpliVity Servers.

HPE Advisory #4 - HPE published an advisory that discusses two vulnerabilities in their SimpliVity Servers.

HPE Advisory #5 - HPE published an advisory that discusses four incomplete cleanup vulnerabilities in their SimpliVity Servers.

HPE Advisory #6 - HPE published an advisory that discusses eleven vulnerabilities in their Moonshot/Edgeline Servers.

HPE Advisory #7 - HPE published an advisory that discusses nine vulnerabilities in their B-Series SANnav Management Portal.

Luxion Advisory - Luxion published an advisory that describes an information disclosure vulnerability in their KeyShot Network Rendering.

Omron Advisory #1 - Omron Advisories - Omron published an advisory that describes an authentication bypass by capture-replay vulnerability in their NJ/NX-series Machine Automation Controllers.

Omron Advisory #2 - Omron published an advisory that describes two vulnerabilities in their NJ/NX-series Machine Automation Controllers.

Philips Advisory - Philips published an advisory that discusses the Follina vulnerability.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-d29 - subscription required.

Wednesday, March 10, 2021

11 Updates Published – 3-9-21

Yesterday the CISA NCCIC-ICS updated eleven control system security advisories for products from Siemens (9), dnsmasq by Simon Kelley, and Luxion.

PROFINET DCP Update

This update provides additional information on an advisory that was originally published on May 9th, 2017 and most recently updated on August 11th, 2020. The new information includes:

• Adding ecoPN model (6ES7148-6JG00-0BB0) as not affected

• Adding MV400 to the affected product list and providing mitigation measures, and

• Updating CWE classification for CVE-2017-2680 and CVE-2017-2681

Industrial Products Update

This update provides additional information on an advisory that was originally published on December 5th, 2017 and most recently updated on August 11th, 2020. The new information includes adding ecoPN model (6ES7148-6JG00-0BB0) as not affected.

SINEMA Update

This update provides additional information on an advisory that was originally published on April 9th, 2019. The new information includes adding CVE-2019-3823, the third-party (libcurl) heap out-of-bounds read vulnerability.

SIMATIC Update #1

This update provides additional information on an advisory that was originally published on June 11th, 2019. The new information includes adding mitigation measures for or MV400.

PROFINET-IO Stack Update

This update provides additional information on an advisory that was originally published on February 11th, 2020 and most recently updated on December 8th, 2020. The new information includes:

• Adding ecoPN model (6ES7148-6JG00-0BB0) as not affected, and

• Adding mitigation information for MV400

NOTE: NCCIC-ICS provided the original publication date not the date of the last update in the Update Information.

KTK Update

This update provides additional information on an advisory that was originally published on April 14th, 2020 and most recently updated on May 12th, 2020. The new information includes adding Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200 (P) to the list of affected products.

SIMATIC Update #2

This update provides additional information on an advisory that was originally published on July 9th, 2020 and most recently updated on January 12th, 2021. The new information includes adding mitigation measures for:

• SINUMERIK ONE Virtual, and

• SINUMERIK Operate

NOTE: NCCIC-ICS missed the date of the previous update in the Update Information of this advisory, providing the one before instead.

UMC Stack Update

This update provides additional information on an advisory that was originally published on July 14th, 2020 and most recently updated on February 9th, 2021. The new information includes adding mitigation measures for SIMATIC IT Production Suite.

Embedded TCP/IP Stack Update

This update provides additional information on an advisory that was originally published on December 12th, 2020 and most recently updated on February 9th, 2021. The new information includes:

• Adding mitigation measures for SIRIUS 3RW5 communication module Modbus TCP, and

• Adding reference to additional AMNESIA:33 advisory (SSA-541018)

DNSMASQ Update

This update provides additional information on an advisory that was originally published on January 19th, 2021. The new information includes publishing a link to the Siemens advisory that was originally published on January 19th, 2021 and updated yesterday.

Luxion Update

This update provides additional information on an advisory that was originally published on February 4th, 2021. The new information includes adding a link to a Siemens advisory for products affected by this vulnerability.

NOTE: Note the Siemens advisory is one of the two unlisted advisories that I mentioned in the close of last night’s blog post.

Other Siemens Updates

Yesterday Siemens published three other updates that were not covered by NCCIC-ICS yesterday. I will discuss them this weekend.

Thursday, February 4, 2021

2 Advisories and 1 Update Published – 2-4-21

Today CISA’s NCCIC-ICS published two control system security advisories for products from Horner Automation and Luxion. They also updated an advisory for products from WAGO.

Horner Advisory

This advisory describes an out-of-bounds read vulnerability in the Horner Cscape control system application programming software. The vulnerability was reported by Francis Provencher via the Zero Day Initiative. Horner has a new version that mitigates the vulnerability. There is no indication that Provencher has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit this vulnerability to allow code execution in the context of the current process.

Luxion Advisory

This advisory describes five vulnerabilities in the Luxion KeyShot 3D rendering and animation software. The vulnerabilities were reported by rgod via ZDI. Luxion has an update that mitigates the vulnerabilities. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

The five reported vulnerabilities are:

• Out-of-bounds write - CVE-2021-22647,

• Out-of-bounds read - CVE-2021-22643,

• Insufficient UI warning of dangerous operation - CVE-2021-22645,

• Untrusted pointer dereference - CVE-2021-22649, and

• Path traversal - CVE-2021-22651

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to allow arbitrary code execution, the storing of arbitrary scripts into automatic startup folders, and the attacking of products without sufficient UI warning.

WAGO Update

This update provides additional information for an advisory that was originally published on January 21st, 2011. The new information includes:

• Adding Weidmüller as an affected vendor,

• Re-writes vulnerability description to expand affect beyond just RTIS products, and

• Added links to Emerson and Weidmüller advisories.

NOTE 1: I reported on the Weidmüller advisory on January 23rd.

NOTE 2: The Rockwell advisory about which I reported on January 30th is still missing from the list of affected vendors.

 
/* Use this with templates/template-twocol.html */