Showing posts with label Microchip. Show all posts
Showing posts with label Microchip. Show all posts

Sunday, April 6, 2025

Review – Public ICS Disclosures – Week of 3-29-25 – Part 2

For Part 2 we have five additional vendor disclosures from Moxa (2), Splunk (2), and VMware. We also have three vendor updates from FortiGuard, HP, and Palo Alto Networks. There are eight researcher reports for vulnerabilities in products from STMicroelectronics (4) and BEC Technologies (4). Finally we have five exploits for products from Broadcom, Microchip (2), Palo Alto Networks, and Splunk.

Advisories

Moxa Advisory #1 - Moxa published an advisory that describes an OS command injection vulnerability in their Secure Routers, Cellular Routers, Network Security Appliances.

Moxa Advisory #2 - Moxa has new firmware versions for most of the affected products.

Splunk Advisory #1 - Splunk published an advisory that discusses three vulnerabilities in their UniversalForwarder Docker product.

Splunk Advisory #2 - Splunk published an advisory that discusses three vulnerabilities in their Splunk Docker product.

VMware Advisory - Broadcom published an advisory that describes an improper privilege management vulnerability in the VMware Aria Operations product.

Updates

FortiGuard Update - FortiGuard published an update for their Authentication bypass in Node.js advisory that was originally published on January 14th, 2025, and most recently updated on February 11th, 2025.

HP Update - HP published an update for their Intel 2024.3 IPU – Chipset advisory that was originally published on October 24th, 2024.

Palo Alto Networks Update - Palo Alto Networks published an update for their GlobalProtect App advisory that was originally published on March 12th, 2025, and most recently updated on March 13th, 2025.

Researcher Reports

STMicroelectronics Reports - Cisco Talos published four reports (including proof-of-concept code) about seven vulnerabilities in the STMicroelectronics X-CUBE-AZRTOS-F7 product.

BEC Technologies Reports - ZDI published four reports about individual vulnerabilities in the BEC Technologies Routers. ZDI reported the vulnerabilities to the vendor but has received no response.

Exploits

Broadcom Exploit - Pierre Kim published an exploit for ten vulnerabilities in the Broadcom Brocade Fabric OS.

Microchip Exploit #1 - Antonio Carriero (et al) published an exploit for an OS command injection vulnerability in the Microchip TimeProvider 4100 Grandmaster product.

Microchip Exploit #2 - Antonio Carriero (et al) published an exploit for a cross-site scripting vulnerability in the Microchip TimeProvider 4100 Grandmaster product.

Palo Alto Networks Exploit - Pierre Kim published an exploit for three deep packet inspection vulnerabilities in the Palo Alto Networks firewalls.

Splunk Exploit - Gunzf0x published an exploit for a path traversal vulnerability in the Splunk Enterprise on Windows product.

 

For more information on these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-9a7 - subscription required.


Saturday, December 24, 2022

Review – Public ICS Disclosures – Week of 12-17-22

This week we have an OpenSSL 3.0 disclosure from Palo Alto Networks. There are nine vendor disclosures from Dahua, Dell, DIGI, Hikvision, HPE, Microchip, Motorola Solutions, TandD, and Western Digital. Finally, there is a vendor update from Siemens.

OpenSSL. 3.0

Palo Alto Networks published an advisory discussing the OpenSSL 3.0 vulnerabilities.

Vendor Disclosures

Dahua Advisory - Dahua published an advisory that describes twelve vulnerabilities in a variety of Dahua products.

Dell Advisory - Dell published an advisory that describes nine vulnerabilities (includes 3 third-party vulnerabilities) in their Wyse Management Suite. 

DIGI Advisory - DIGI published an advisory that discusses the FragAttack vulnerabilities.

Hikvision Advisory - Hikvision published an advisory that describes an access control vulnerability in their wireless bridge products.

HPE Advisory #1 - HPE published an advisory that directory traversal vulnerability in their OfficeConnect 1820, and 1850 Switch Series.

HPE Advisory #2 - HPE published an advisory that describes a data injection vulnerability in their Superdome Flex and Superdome Flex 280 Servers.

Microchip Advisory - Microchip published an advisory that discusses the Blue's Clues vulnerabilities.

NOTE: Watch Blue’s Clues (sorry, I could not help myself), cute name and everything. It looks like this will be a major issue for Bluetooth enabled devices, particularly medical devices.

Motorola Advisory - Motorola published an advisory discussing the Fortinet buffer overflow vulnerability.

TandD Advisory - TandD published an end of support notice for products operating on Windows 7 and Windows 8 platforms.

Western Digital Advisory - Western Digital published an advisory describing an information disclosure vulnerability in their My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.

Vendor Updates

Siemens Update - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-349-14) for the new information.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-f5b - subscription required.

 
/* Use this with templates/template-twocol.html */