Showing posts with label MedDream. Show all posts
Showing posts with label MedDream. Show all posts

Sunday, January 25, 2026

Review – Public ICS Disclosures – Week of 1-17-26

For Part 2 we have 2 additional vendor disclosures from Rockwell. There are also five vendor updates from ABB, FortiGuard, HPE, Siemens, and VMware. We have bulk researcher reports for products from MedDream (22). Finally, we have two exploit for products from Splunk.

Advisories

Rockwell Advisory #1 - Rockwell published an advisory that describes nine uncontrolled resource consumption vulnerabilities in their ArmorStart LT product.

Rockwell Advisory #2 - Rockwell published an advisory that describes a missing release of memory after effective lifetime vulnerability in their 1756-RM2(XT).

Updates

ABB Update - ABB published an update for their ABB 800xA Base advisory that was originally published on June 5th, 2024, and most recently updated on February 7th, 2025.

FortiGuard Update - FortiGuard published an update for their cw_acd daemon advisory that was originally published on January 13th, 2026.

HPE Update - HPE published an update for their Aruba Networking Access Points advisory that was originally published on August 3rd, 2024, and most recently updated on March 14th, 2025.

Siemens Update - Siemens published an update for their RUGGEDCOM APE1808 Devices advisory that was originally published on May 13th, 2025, and most recently updated on January 13th, 2026.

Bulk Researcher Reports – MedDream (22)

MedDream PACS Premium modifyUser reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium emailfailedjob reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyTranscript reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium downloadZip reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium downloadZip reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium autoPurge reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyAnonymize reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyEmail reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyCoercion reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyHL7Route reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium existingUser reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium ldapUser reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium notifynewstudy reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium encapsulatedDoc arbitrary file read vulnerability,

MedDream PACS Premium modifyRoute reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium sendOruReport reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium encapsulatedDoc reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyHL7App reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium config.php multiple reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium fetchPriorStudies reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyAutopurgeFilter reflected cross-site scripting (XSS) vulnerability,

MedDream PACS Premium modifyAeTitle reflected cross-site scripting (XSS) vulnerability

NOTE: These CISCO Talos reports include proof-of-concept code.

Exploits

Splunk Exploit #1 - Alex Hordijk published a Metasploit module for a function call with an incorrectly specified argument value vulnerability in the Splunk Enterprise product.

Splunk Exploit #2 - Psytester published a Metasploit module for code injection vulnerability in the Splunk Enterprise product.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-aab - subscription required.

Sunday, August 3, 2025

Review – Public ICS Disclosures – Week of 7-26-25 – Part 2

For Part 2 this week we have an additional vendor disclosure from HPE. There are also four vendor updates from Broadcom, and HP (3). We also have 35 researcher reports for vulnerabilities in products from Eclipse, Ilevia (2), MedDream (4), QNAP (26), and Tesla (2). Finally, we have two exploits for products from AK-Nord and Helmholz.

Advisories

HPE Advisory - HPE published an advisory that discusses 12 vulnerabilities in their Telco Network Function Virtual Orchestrator product.

Updates

Broadcom Update - Broadcom published an update for their GNU Glibc advisory that was originally published on July 8th, 2025.

HP Update #1 - HP published an update for their Intel 2025.1 IPU Chipset advisory that was originally published on March 10th, 2025.

HP Update #2 - HP published an update for their UEFI Firmware advisory that was originally published on February 3rd, 2022, and most recently updated on May 28th, 2025.

HP Update #3 - HP published an update for their Intel PROSet/Wireless WiFi advisory that was originally published on March 13th, 2025, and most recently updated on July 11th, 2025.

Researcher Reports

Eclipse Report - Cisco Talos published a report about a buffer overflow vulnerability in the Eclipse ThreadX FileX RAM disk driver.

Ilevia Reports - Zero Science published two reports about vulnerabilities in the Ilevia EVE X1 Server. The report includes a link to exploit code.

MedDream Reports - Cisco Talos published four reports of vulnerabilities in the MedDream PACS Premium product. The reports include proof-of-concept code.

QNAP Reports #1 - ZDI published three reports about vulnerabilities in the QNAP TS-464 Samba.

QNAP Reports #2 - ZDI published 15 reports about vulnerabilities in the QNAP QHora-322 product.

QNAP Reports #3 - ZDI published 8 reports about vulnerabilities in the QNAP TS-464 product.

Tesla Reports - ZDI published two reports about vulnerabilities in the Tesla Wall Connector product.

Exploits

AK-Nord Exploit - Marcus Krüppel published an exploit for an insecure permissions vulnerability in the AK-Nord USB-Server-LXL Firmware.

Helmholz Exploit - M. Kadlec et al published an exploit for nine vulnerabilities in the Helmholz REX100 industrial router.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-782 - subscription required.

Sunday, April 27, 2025

Review – Public ICS Disclosures – Week of 4-19-25 – Part 2

For Part 2 we have two additional vendor disclosures from Trumpf, and Zyxel. There are five vendor updates from FortiGuard (2), HPE, Palo Alto Networks, and Rockwell Automation. There are six researcher reports for products from SonicWall and MedDream (5). Finally, we have an exploit for products from OpenSSH.

Advisories

Trumpf Advisory - CERT-VDE published an advisory that discusses an improper restriction of XML external entity reference vulnerability in multiple Trumpf products.

Zyxel Advisory - Zyxel published an advisory that describes two vulnerabilities in their USG FLEX H series firewalls.

Updates

FortiGuard Update #1 - FortiGuard published an update for their RADIUS Protocol advisory that was originally published on August 13th, 2024, and most recently updated on March 14th, 2025.

FortiGuard Update #2 - FortiGuard published an update for their fgfm connection advisory that was originally published on April 8th, 2025, and most recently updated on April 11th, 2025.

HPE Update - HPE published an update for their Cray Data Virtualization Service advisory that was originally published on April 18th, 2025.

Palo Alto Networks Update - Palo Alto Networks published an update for their GlobalProtect App advisory that was originally published on April 9th, 2025, and most recently updated on April 11th, 2025.

Rockwell Update - Rockwell published an update for their ThinManager advisory that was originally published on April 15th, 2025.

Researcher Reports

SonicWall Report - BishopFox published a report on a NULL pointer dereference vulnerability in the SonicWall Sonic OS product.

MedDream Reports - ZDI published five reports describing individual vulnerabilities in the MedDream PACS Server.

Exploits

OpenSSH Exploit - Milad Karimi published an exploit for a race condition vulnerability in the OpenSSH server.

 

For more information on these disclosures, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-d2e - subscription required.

Monday, April 14, 2025

Review – Public ICS Disclosures – Week of 4-5-25 – Part 3

For Part 3 we have 23 vendor updates from Dell, FortiGuard, HP, Schneider (4), and Siemens (16). There are five researcher reports for vulnerabilities in products from MedDream. Finally, we have two exploits for products from HMS and Palo Alto Networks.

Updates

Dell Update - Dell published an update for their ThinOS advisory that was originally published on March 4th, 2025, and most recently updated on March 18th, 2025.

FortiGuard Update - FortiGuard published an update for their ipsec ike advisory that was originally published on January 14th, 2025.

HP Update - HP published an update for their PC BIOS advisory that was originally published on October 24th, 2024.

Schneider Update #1 - Schneider published an update for their Modicon M580 PLCs advisory that was originally published on January 14th, 2025.

Schneider Update #2 - Schneider published an update for their VxWorks DHCP server advisory that was originally published on January 14th, 2025.

Schneider Update #3 - Schneider published an update for their Modicon Controllers M340 advisory that was originally published on November 12th, 2024.

Schneider Update #4 - Schneider published an update for their BadAlloc Vulnerabilities advisory that was originally published on November 9th, 2021, and most recently updated on January 14th, 2025.

Siemens Update #1 - Siemens published an update for their FTP Server of Nucleus RTOS advisory that was originally published on October 11th, 2022, and most recently updated on May 14th, 2024.

Siemens Update #2 - Siemens published an update for their Frame Aggregation advisory that was originally published on July 13th, 2021, and most recently updated on April 12th, 2022.

Siemens Update #3 - Siemens published an update for their SIMATIC S7-1500 advisory that was originally published on October 8th, 2024, and most recently updated on March 11th, 2025.

Siemens Update #4 - Siemens published an update for their Fortigate NGFW advisory that was originally published on February 11th, 2025, and most recently update on March 11th, 2025. Includes adding a new vulnerability with publicly available exploits.

Siemens Update #5 - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on February 11th, 2025, and most recently updated on March 11th, 2025.

Siemens Update #6 - Siemens published an update for their Fortigate NGFW advisory that was originally published on July 9th, 2024, and most recently updated on February 11th, 2025.

Siemens Update #7 - Siemens published an update for their Siemens Industrial Products advisory that was originally published on February 14th, 2023, and most recently updated on August 13th, 2024.

Siemens Update #8 - Siemens published an update for their SIMATIC S7-1500 TM MFP advisory that was originally published on March 11th, 2025.

Siemens Update #9 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2023, and most recently update on March 11th, 2025.

Siemens Update #10 - Siemens published an update for their SIMATIC IPC DiagBase advisory that was originally published on February 11th, 2025.

Siemens Update #11 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on July 9th, 2024, and most recently updated on December 10th, 2024.

Siemens Update #12 - Siemens published an update for their Palo Alto Networks PAN-OS advisory that was originally published on November 22nd, 2024, and most recently updated on February 19th, 2025.

Siemens Update #13 - Siemens published an update for their Insyde BIOS advisory that was originally published on February 22nd, 2022, and most recently updated on November 14th, 2023.

Siemens Update #14 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on March 9th, 2024, and most recently updated on November 12th, 2024. – Includes adding vulnerability that is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Siemens Update #15 - Siemens published an update for their Webserver of SIMATIC Products advisory that was originally published on February 11th, 2025, and most recently updated on March 11th, 2025.

Siemens Update #16 - Siemens published an update for their Web Server of SIMATIC S7-1500 CPUs advisory that was originally published on October 8th, 2024, and most recently updated on March 11th, 2025.

Researcher Reports

MedDream Reports - ZDI published five reports describing individual vulnerabilities in the MedDream PACS Server. The

Exploits

HMS Exploit - CodeB0ss published an exploit for an OS command injection vulnerability in the HMS Cosy+ devices.

Palo Alto Networks Exploit - ByteHunter published an exploit for a missing authentication for critical function vulnerability in the Palo Alto Networks Expedition product.

 

For more information about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-741 - subscription required.
 
/* Use this with templates/template-twocol.html */