Showing posts with label Milesight. Show all posts
Showing posts with label Milesight. Show all posts

Thursday, April 23, 2026

Review – 6 Advisories and 1 Update Published – 4-23-26

 Today CISA’s NCCIC-ICS published six control system security advisories for products from Intrado, Hangzhou Xiongmai Technology Co, SpiceJet, Milesight, Carlson Software, and YADEA. There is also an update for an advisory for products from Schneider Electric. I also take a down-the-rabbit-hole look at a second Hangzhou vulnerability. 

Advisories  

Intrado Advisory This advisory describes a path traversal vulnerability in the Intrado 911 Emergency Gateway. 

Hangzhou Advisory This advisory describes a missing authentication for critical function vulnerability in the Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera. 

SpiceJet Advisory - This advisory describes two vulnerabilities in the SpiceJet Online Booking System. 

Milesight Advisory - This advisory describes five vulnerabilities in multiple Milesight Cameras. 

Carlson Advisory This advisory describes a missing authentication for critical function vulnerability in the Carlson Software VASCO-B GNSS Receiver. 

Yadea Advisory This advisory describes a weak authentication vulnerability in the Yadea T5 Electric Bicycle. 

Updates  

Schneider Update - This update provides additional information on the Modicon Controllers advisory that was originally published on April 23rd, 2026. 


For more information on these advisories, including a down-the-rabbit-hole look at an additional Hangzhou vulnerabilitysee my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-6ff - subscription required. 

Tuesday, May 6, 2025

Review – 3 Advisories Published – 5-6-25

Today CISA’s NCCIC-ICS published three control system security advisories for products from BrightSign, Milesight, and Optigo Networks.

Advisories

BrightSign Advisory - This advisory describes an execution with unnecessary privileges vulnerability in the BrightSign OS.

Milesight Advisory - This advisory describes an improper access control for volatile memory containing boot code vulnerability in the Milesight UG65-868M-EA industrial gateway.

Optigo Advisory - This advisory describes a use of hard-coded credentials vulnerability in the Optigo ONS NC600 network controller.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-published-5-6-25 - subscription required.

Saturday, February 10, 2024

Review – Public ICS Disclosure – Week of 2-3-24

This week we have 22 vendor disclosures from Badger, B&R Automation (2), FortiGuard (4), GE Vernova, Hitachi (2), HPE, Meinberg, Pilz, SEL, Sharp, VMware, WatchGuard (4), and Western Digital. There is also one update from HP. Finally, we have three exploits for products from Forta, Milesight, and Zyxel.

Advisories

Badger Advisory - Incibe-CERT published an advisory that describes four vulnerabilities in their Monitool product.

B&R Advisory #1 - B&R published an advisory that describes a use of broken or risky cryptographic algorithm in their Runtime FTP server component.

B&R Advisory #2 - B&R published an advisory that describes a cross-site scripting vulnerability in their SDM Web interface.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an out-of-bounds write vulnerability (listed in CISA’s Known Exploit Exploits Catalog) in their FortiOS.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes a lack of certificate validation vulnerability in their FortiOS.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a use of externally-controlled format string vulnerability.

FortiGuard Advisory #4 - FortiGuard published an advisory that discusses an uncontrolled resource consumption vulnerability (which is listed in CISA’s KEV) in their FortiOS and FortiProxy products.

GE Advisory - GE published an advisory that discusses a use of externally controlled format string vulnerability in their NetworkST4 and Remote Operations Offering.

Hitachi Advisory #1 - Hitachi published an advisory that discusses ten vulnerabilities in multiple Hitachi products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses two vulnerabilities in their JP1 product.

HPE Advisory - HPE published an advisory that discusses 17 vulnerabilities in their Unified OSS Console Assurance Monitoring (UOCAM).  

Meinberg Advisory - Meinberg published an advisory that discusses 18 vulnerabilities in their LANTIME-Firmware.

Pilz Advisory - Pilz published an advisory that discusses six vulnerabilities.

SEL Advisory - SEL published an update notice for a new version of their SEL-5025 Secure Port Software which fixes two security issues.

Sharp Advisory - Sharp published an advisory that describes a path traversal vulnerability in multiple Sharp public display products.

VMware Advisory - VMware has published an advisory that describes five vulnerabilities in their VMware Aria Operations for Networks product.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes a memory corruption vulnerability in their Endpoint products.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes an out-of-bounds write vulnerability in their Endpoint products.

WatchGuard Advisory #3 - WatchGuard published an advisory that describes an arbitrary kernel read vulnerability in their Endpoint products.

WatchGuard Advisory #4 - WatchGuard published an advisory that discusses four Ivanti vulnerabilities.

Western Digital Advisory - Western Digital published an advisory that describes two vulnerabilities in their My Cloud, WD Cloud, and SanDisk ibi products.

Updates

HP Update - HP published an update for their UC Software advisory that was originally published on January 9th, 2024.

Exploits

Forta Exploit - James Horseman published an Metasploit module for a forced browsing vulnerability in the Forta GoAnywhere MFT.

Zyxel Exploit - Marco Ivaldi published an exploit for an improper input validation vulnerability in multiple Zyxel products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-2-3 - subscription required.

Saturday, July 8, 2023

Review – Public ICS Disclosures – Week of 7-1-23

This week we have eleven vendor disclosures from Aruba Networks, Bosch (2), Enphase, Frauscher Sensortechnik, Hikvision, Moxa, Softing (2), VMware and Zyxel. And we have 29 researcher reports for products from Panasonic (3), Milesight (25), and Siemens.

Advisories

Aruba Advisory - Aruba published an advisory that describes nine vulnerabilities in the Aruba OS products.

Bosch Advisory #1 - Bosch published an advisory that discusses two vulnerabilities in their FL MGUARD family devices.

Bosch Advisory #2 - Bosch published an advisory that discusses a missing authentication for critical function vulnerability in their SLC-0-GPNT00300 interface module.

Enphase Advisory - Enphase published an advisory that describes an OS command injection vulnerability in their Enphase IQ Gateway (Envoy).

Frauscher Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1.

Hikvision Advisory - Hikvision published an advisory that describes two vulnerabilities in their access control/intercom products.

Moxa Advisory - Moxa published an advisory that describes an observable response discrepancy vulnerability in their TN-5900 Series product.

Softing Advisory #1 - Softing published an advisory that describes two vulnerabilities in their OPC UA C++ SDK and Secure Integration Server.

Softing Advisory #2 - Softing published an advisory that describes an uncontrolled resource consumption vulnerability in a number of their products.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their SD-WAN (Edge) product.

Zyxel Advisory - Zyxel published an advisory that describes a classic buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Researcher Reports

Panasonic Reports - AWESEC published three reports describing individual vulnerabilities in the Panasonic Panasonic AiSEG2.

Milesight Reports - Talos Intelligence published 25 reports (some with multiple vulnerabilities) for the Milesight UR32L urvpn_client and MilesightVPN server.

Siemens Report - SEC Consult published a report describing the four vulnerabilities in the Siemens A8000 product.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-bcb - subscription required.

 
/* Use this with templates/template-twocol.html */