Showing posts with label Peplink. Show all posts
Showing posts with label Peplink. Show all posts

Saturday, April 20, 2024

Review – Public ICS Disclosures – Week of 4-13-24

This week we have nine vendor disclosures from Hitachi, HPE (4), Peplink, Philips, and Rockwell (2). There are also five vendor updates from B&R (2), Contec, HPE, and Palo Alto Networks. We also have eleven researcher reports about vulnerabilities in products from Elber (10) and Silicon Labs. Finally, we have two exploits for products from Palo Alto Networks.

NOTE: HP reports that they have an update for their NVIDIA GPU Display Driver advisory that was originally published on March 12th, 2024, but the link currently goes to a blank page.

Advisories

Hitachi Advisory - Hitachi published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their JP1 product.

HPE Advisory #1 - HPE published an advisory that discusses an out-of-bounds write vulnerability in their Superdome Flex, Superdome Flex 280 and Compute Scale-up Server 3200 Servers.

HPE Advisory #2 - HPE published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in their Compute Scale-up Server 3200 server.

HPE Advisory #3 - HPE published an advisory that discusses five vulnerabilities (three with exploits available) in their Telco IP Mediation E-Media product.

HPE Advisory #4 - HPE published an advisory that describes an insertion of sensitive information into a logfile vulnerability in their Compute Scale-up Server 3200 Server.

Peplink Advisory - Peplink published an advisory that describes five vulnerabilities in their Smart Reader access control product.

Philips Advisory - Philips published an advisory that discusses a CISA report of a compromise of Sisense Customer Data.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their 5015-AENFTXT product.

Rockwell Advisory #2 - Rockwell published an advisory that discusses a deserialization of untrusted data vulnerability {listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog} in their FactoryTalk Production Centre product.

Updates

B&R Update #1 - B&R published an update for their Docker Engine advisory that was originally published on April 10th, 2024.

B&R Update #2 - B&R published an update for their LOGO Fail advisory that was originally published on April 11th, 2024.

Contec Update - JP-CERT published an update for their SolarView Compact advisory that was originally published on June 9th, 2022 and most recently updated on February 10th, 2023.

HPE Update - HPE published an update for their Superdome Flex advisory that was originally published on January 23rd, 2024 and most recently updated on March 8th, 2024.

Palo Alto Networks Update - Palo Alto Networks published an update for their PAN OS command injection advisory that was originally published on March 12th, 2024.

Researcher Reports

Elber Report #1 - Zero Science published two reports of vulnerabilities in the Elber Signum DVB-S/S2 controller for satellite equipment.

Elber Report #2 - Zero Science published two reports of vulnerabilities in the Elber Cleber/3 Broadcast Multi-Purpose Platform.

Elber Report #3 - Zero Science published two reports of vulnerabilities in the Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link.

Elber Report #4 - Zero Science published two reports of vulnerabilities in the Elber DVB-S/S2 Satellite Receiver. Microwave Link.

Elber Report #5 - Zero Science published two reports of vulnerabilities in the Elber Wayber Analog/Digital Audio STL.

Silicon Labs Report - Talos published a report about a NULL pointer dereference vulnerability in the Silicon Labs Gecko Platform software design kit.

Exploits

Palo Alto Networks Exploit #1 - H4x0r-dz published an exploit for a command injection vulnerability in the Palo Alto Networks PAN-OS.

Palo Alto Networks Exploit #2 - W01fh4cker published an exploit for a command injection vulnerability in the Palo Alto Networks PAN-OS.

 

For more details about these disclosures, including links to researcher report, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-ac1 - subscription required.

Saturday, October 14, 2023

Review – Public ICS Disclosures – Week of 10-7-23 – Part 1

This week we have 19 vendor disclosures from Cisco, FortiGuard (5), Insyde, Palo Alto Networks (3), Pilz, QNAP (4), Rockwell Automation, Sick, Synology, and Zebra Technologies. There is a vendor update from Cisco. Finally, for Part 1 anyway, we have 22 researcher reports for products from Peplink (4), SoftEther (9), and Yifan (9).

For Part 2 we will have disclosures and updates from Schneider and Siemens and five control system exploits.

Advisories

Cisco Advisory - Cisco published an advisory that discusses the recently announced SOCKS5 handshake vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an access control vulnerability in their FortiOS products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an information disclosure vulnerability in their FortiOS products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes an improper authorization vulnerability in their FortOS products.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiOS products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes a use after free vulnerability in their FortiOS and FortiProxy products.

Insyde Advisory - Insyde published an advisory that describes an incorrect information reporting vulnerability in their TrEEConfigDriver.

Palo Alto Networks Advisory # 1 - Palo Alto Networks published an advisory that discusses the Rapid Reset vulnerability.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a clear-text storage of sensitive information vulnerability in their Cortex XSOAR product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that discusses the announced SOCKS5 handshake vulnerability.

Pilz Advisory - CERT VDE published an advisory that discusses two vulnerabilities in multiple Pilz products.

QNAP Advisory #1 - QNAP published an advisory that describes three vulnerabilities in their Video Station product.

QNAP Advisory #2 - QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes a path traversal vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #4 - QNAP published an advisory that describes an OS command injection vulnerability in their Container Station product.

Rockwell Advisory - Rockwell published an advisory that describes an improper input validation vulnerability in their FactoryTalk Linx product.

Sick Advisory - Sick published an advisory that describes nine vulnerabilities in their Application Processing Unit.

Synology Advisory - Synology published an advisory that discusses the Rapid Reset Vulnerability.

Zebra Advisory - INCIBE CERT published an advisory that describes an authentication bypass using an alternate path or channel in the Zebra  ZTC ZT410-203dpi ZPL printers.

Updates

Cisco Update - Cisco published an update for their Adaptive Security Appliance Software advisory that was originally published on September 6th, 2023, and most recently updated on September 29th, 2023.

Researcher Reports

Peplink Reports - Cisco Talos published four reports about vulnerabilities in the Peplink Surf SOHO HW1 routers.

SoftEther Reports - CISCO Talos published 9 reports on vulnerabilities in the VPN product from SoftEther.

Yifan Reports - Cisco Talos published nine reports about vulnerabilities in the Yifan YF325 industrial cellular router.

 

For more details about these disclosures, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-a73 - subscription required.

 
/* Use this with templates/template-twocol.html */