Showing posts with label National Instruments. Show all posts
Showing posts with label National Instruments. Show all posts

Sunday, July 27, 2025

Review – Public ICS Disclosures – Week of 7-19-25 – Part 2

For Part 2 we have two additional vendor disclosures from National Instruments and Supermicro. We also have eight vendor updates from Broadcom (7) and Siemens.

Advisories

National Instruments Advisory - NI published an advisory that describes two vulnerabilities in their LabVIEW product. The vulnerabilities were reported by Michale Heinzl.

Supermicro Advisory - Supermicro published an advisory that discusses four transient execution vulnerabilities in multiple products.

Updates

Broadcom Update #1 - Broadcom published an update for their Linux Kernel advisory that was originally published on July 8th, 2025.

Broadcom Update #2 - Broadcom published an update for their GNU Glibc Kernel advisory that was originally published on July 8th, 2025.

Broadcom Update #3 - Broadcom published an update for their Linux Kernel advisory that was originally published on July 8th, 2025.

Broadcom Update #4 - Broadcom published an update for their Linux Kernel SUN RPC Subsystem advisory that was originally published on July 8th, 2025.

Broadcom Update #5 - Broadcom published an update for their Linux Kernel Vulnerable to Dangling Pointer advisory that was originally published on June 10th, 2025, and most recently updated on June 15th, 2025.

Broadcom Update #6 - Broadcom published an update for their Denial-of-Service advisory that was originally published on July 8th, 2025.

Broadcom Update #7 - Broadcom published an update for their Path Transversal advisory that was originally published on June 10th, 2025.

Siemens Update - Siemens published an update for their Denial of Service of ICMP advisory that was originally published on April 8th, 2025, and most recently updated on July 10th, 2025.

 

For more information on these disclosures, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-b0f - subscription required.

Saturday, March 22, 2025

Review – Public ICS Disclosures – Week of 3-15-25

This week we have 24 vendor disclosures from CODESYS (3), Dassault Systèmes (13), Fuji Soft, Helmholtz, HPE (2), MB Connect, Phillips (2), and QNAP. There are also six vendor updates from Dell, FortiGuard (3), HP, and HPE. Finally, there are three researcher reports for vulnerabilities in products from Luxion and National Instruments (2).

Advisories

CODESYS Advisory #1 - CODESYS published an advisory that describes an observable discrepancy vulnerability in their  CODESYS Runtime Toolkit.

CODESYS Advisory #2 - CODESYS published an advisory that describes a path traversal vulnerability in multiple CODESYS products.

CODESYS Advisory #3 - CODESYS published an advisory that describes an insecure initialization of resource vulnerability in Edge Gateway for Windows and Gateway for Windows products.

Dassault Advisories - Dassault Systèmes published 13 advisories stored cross-site scripting vulnerabilities in multiple products. These advisories are only available to registered customers.

Fuji Soft Advisory - JP-CERT published an advisory that describes two command OS injection vulnerabilities in the Fuji F FS010M router.

Helmholtz Advisory - CERT-VDE published an advisory that describes two vulnerabilities in the Helmholtz  myREX24 and myREX24.virtual products.

HPE Advisory #1 - HPE published an advisory that describes three vulnerabilities in the HPE Aruba Networking AOS-CX product.

HPE Advisory #2 - HPE published an advisory that discusses six vulnerabilities (two with publicly available exploits) in their Telco Service Activator.

MB Connect Advisory - CERT-VDE published an advisory that describes two vulnerabilities in multiple MB Connect products.

Philips Advisory #1 - Philips published an advisory that discusses an Apache Tomcat vulnerability.

Philips Advisory #2 - Philips published an advisory that discusses three VMware vulnerabilities.

QNAP Advisory - QNAP published an advisory that discusses an absolute path traversal vulnerability (listed in CISA’s KEV catalog) in the NAKIVO Backup & Replication application.

Updates

Dell Update - Dell published an update for their ThinOS advisory that was originally published on March 4th, 2025.

FortiGuard Update #1 - FortiGuard published an update for their csfd daemon advisory that was originally published on January 14th, 2025, and most recently updated on January 16th, 2025.

FortiGuard Update #2 - FortiGuard published an update for their RADIUS Protocol advisory that was originally published on August 13th, 2024, and most recently updated on March 6th, 2025.

FortiGuard Update #3 - FortiGuard published an update for their permission escalation advisory that was originally published on February 11th, 2025.

HP Update - HP published an update for their LaserJet Pro advisory that was originally published on February 14th, 2025, and most recently updated on March 14th, 2025.

HPE Update - HPE published an update for their Cray XD670 Server advisory that was originally published on March 11th, 2025.

Researcher Reports

Luxion Reports - ZDI published three reports about vulnerabilities in the Luxion KeyShot product.

National Instruments Report #1 - ZDI published a report that describes a path traversal vulnerability in the NI FlexLogger.

National Instruments Report #2 - ZDI published a report that describes a product UI does not warn user of unsafe actions vulnerability in the NI Vision Builder AI.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-daf - subscription required.

Tuesday, December 10, 2024

Review – 6 Advisories and 1 Update Published – 12-10-24

Today CISA’s NCCIC-ICS published six control-system security advisories for products from Rockwell Automation, Horner Automation, National Instruments, Schneider Electric (2), and MOBATIME. They also updated an advisory for products from Ruijie.

Advisories

Rockwell Advisory - This advisory describes four vulnerabilities in the Rockwell Arena product.

Horner Advisory - This advisory describes two out-of-bounds read vulnerabilities in the Horner Cscape product.

National Instruments Advisory - This advisory describes three out-of-bounds read vulnerabilities in the National Instruments Lab View product.

Schneider Advisory #1 - This advisory describes a path traversal vulnerability in the Schneider FoxRTU Station.

Schneider Advisory #2 - This advisory describes three vulnerabilities in the Schneider EcoStruxure Foxboro DCS Core Control Services.

MOBATIME Advisory - This advisory describes a use of default credentials vulnerability in the MOBATIME Network Master Clock - DTS 4801.

Updates

Ruijie Update - This update provides additional information on the Reyee OS advisory that was originally published on December 3rd, 2024.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-88e - subscription required. 

Saturday, July 27, 2024

Review – Public ICS Disclosures – Week of 7-20-24

This week we have two CrowdStrike outage advisories. We also have 18 other vendor advisories for products from Broadcom, Draeger, Hitachi, HPE (4), Meinberg, National Instruments (7), WithSecure (2), and Zyxel. We have three vendor updates from Cisco (2) and HP. There is also a researcher report for vulnerabilities in products from Perkin Elmer. Finally, we have an exploit for products from Softing.

CrowdStrike Outage

GE Vernova published an advisory that discussed the impact on some of their Monitoring & Diagnostics products.

Philips published an advisory that provides a list of potentially affected products.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses ten vulnerabilities in the Azul Zulu component of their Brocade SANnav product.

Draeger Advisory - Draeger published an advisory that discusses a deserialization of untrusted data vulnerability (listed in the CISA Known Exploited Vulnerability Catalog).

Hitachi Advisory - Hitachi published an advisory that discusses 27 vulnerabilities in their Disk Array Systems.

HPE Advisory #1 - HPE published an advisory that describes three vulnerabilities in their Aruba EdgeConnect SD-WAN Orchestrator.

HPE Advisory #2 - HPE published an advisory that discusses 21 vulnerabilities (6 with known exploits) in their Unified OSS Console Assurance Monitoring (UOCAM) product.

HPE Advisory #3 - HPE published an advisory that discusses seven vulnerabilities (one with known exploit) in their Aruba EdgeConnect SD-WAN Gateways.

HPE Advisory #4 - HPE published an advisory that discusses an out-of-bounds write vulnerability in their ProLiant DL/ML/SY/XL and Alletra Servers.

Meinberg Advisory - Meinberg published an advisory that discusses ten vulnerabilities (2 with known exploits) in their Lantime product.

National Instruments Advisory #1 - National Instruments published an advisory that describes two missing authorization vulnerabilities in their VeriStand Gateway product.

National Instruments Advisory #2 - National Instruments published an advisory that describes two deserialization of untrusted data vulnerabilities in their VeriStand product.

National Instruments Advisory #3 - National Instruments published an advisory that describes a path traversal vulnerability in their VeriStand product.

National Instruments Advisory #4 - National Instruments published an advisory that describes a deserialization of untrusted data vulnerability in their VeriStand Project File product.

National Instruments Advisory #5 - National Instruments published an advisory that describes an integer overflow or wraparound vulnerability in their TDMS Files in LabVIEW.

National Instruments Advisory #6 - National Instruments published an advisory that describes an incorrect default permissions vulnerability in their SystemLink Redis Service.

National Instruments Advisory #7 - National Instruments published an advisory that describes an out-of-date component with multiple vulnerabilities vulnerability in their SystemLink Server.

WithSecure Advisory #1 - WithSecure published an advisory that describes a denial of service vulnerability in their WithSecure Mac antivirus software.

WithSecure Advisory #2 - WithSecure published an advisory that describes a privilege escalation vulnerability in their WithSecure Mac Products.

Zyxel Advisory - Zyxel published an advisory that describes an improper privilege management vulnerability in their Zyxel AP products.

Updates

Cisco Update #1 - Cisco published an update for their Blast-Radius advisory that was originally published on July 10th, and most recently updated on July 19th, 2024.

Cisco Update #2 - Cisco published an update for their regreSSHion advisory that was originally published on July 2nd, 2024, and most recently updated on July 19th, 2024.

HP Update - HP published an update for their Display Control Software advisory that was originally published on July 15th, 2024.

Researcher Reports

Perkin Elmer Report - Cyber Danube published a report that describes three vulnerabilities in the Perkin Elmer ProcessPlus measurement software.

Exploits

Softing Exploit - Mr me published a Metasploit module for two vulnerabilities in the Softing Secure Integration Server.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-d58 - subscription required.

Tuesday, July 23, 2024

Review – 3 Advisories and 1 Update – 7-23-24

Today, CISA’s NCCIC-ICS published control system security advisories for products from National Instruments (2) and Hitachi Energy. They also published an update for products from Mitsubishi.

Advisories

National Instruments Advisory #1 - This advisory describes three vulnerabilities in the NI LabVIEW product.

National Instruments Advisory #2 - This advisory describes a stack-based buffer overflow vulnerability in the NI I/O TRACE products.

Hitachi Energy Advisory - This advisory discusses four vulnerabilities in the Hitachi Energy AFS/AFR series managed switches.

Hitachi Energy Update - This update provides additional information on the IED Connectivity Packages advisory that was originally published on November 29th, 2022.

 

For more information on these advisories, including links to 3rd party advisories and researcher reports, see  my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/3-advisories-and-1-update-7-23-24 - subscription required.

Thursday, December 3, 2020

1 Advisory and 2 Updates Published – 12-3-20

Today the CISA NCCIC-ICS published one control system security advisory for products from National Instruments. They also updated two advisories for products from Wibu-Systems and WECON.

National Instruments Advisory

This advisory describes an incorrect permission assignment for critical resource vulnerability in the National Instruments CompactRIO real-time embedded industrial controller. The vulnerability was reported by Titanium Industrial Security via Incibe CERT. National Instruments has a new driver that mitigates the vulnerability. There is no indication that researchers have been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to  allow an attacker to reboot the device remotely.

CodeMeter Update

This update provides additional information on an advisory that that  was originally published on September 8th, 2020 and most recently updated on October 15th, 2020. The new information includes links to vendor advisories for products from:

• Eaton, and

• TRUMPF

NOTE: I briefly discussed the Eaton advisory back in early October and the TRUMPF advisory later that month. NCCIC-ICS has not yet mentioned the ENDRESS+HAUSER advisory that I mentioned in the same blog post as the TRUMPF advisory.

WECON Update

This update provides additional information on an advisory that was originally published on August 25, 2020 and most recently updated on October 29th, 2020. The new information includes:

• Adding a new vulnerability (heap-based buffer overflow - CVE-2020-25199), and

• Adding a new reporting researcher (Peter Cheng from Elex Cybersecurity Inc)

 
/* Use this with templates/template-twocol.html */