Showing posts with label Petrol Pump. Show all posts
Showing posts with label Petrol Pump. Show all posts

Saturday, April 6, 2024

Review – Public ICS Disclosures – Week of 3-30-24

This week we have five vendor disclosures about the XZ Utils vulnerability from Broadcom, Palo Alto Networks, Philips, QNAP, and WatchGuard. We have fourteen additional vendor disclosures from ABB, BD, Broadcom (2), Cisco, Hikvision, HP, HPE (4), Palo Alto Networks, Philips, and VMWare. There are four vendor updates from Eaton, HP (2), and HPE. We have five researcher reports for vulnerabilities in products from Open Automation Software (4) and Positron. Finally, we have an exploit for products from Petrol Pump.

XZ Utils Advisories

Broadcom published an advisory that discussed the XZ Utils vulnerability.

Palo Alto Networks published an advisory that discussed the XZ Utils vulnerability.

Philips published an advisory that discussed the XZ Utils vulnerability.

QNAP published an advisory that discussed the XZ Utils vulnerability.

WatchGuard published an advisory that discussed the XZ Utils vulnerability.

Advisories

ABB Advisory - ABB published an advisory that describes an improper input validation vulnerability in the Virtual PNI API in their S+ Engineering product.

BD Advisory - BD published an advisory that discusses an improper privilege management vulnerability in a number of their products.

Broadcom Advisory #1 - Broadcom published an advisory that describes an OS command injection vulnerability in their Brocade Fabric OS product.

Broadcom Advisory #2 - Broadcom published an advisory that describes an origin validation error vulnerability in their Brocade Fabric OS product.

Cisco Advisory - Cisco published an advisory that describes two vulnerabilities in their Emergency Responder product.

Hikvision Advisory - Hikvision published an advisory that describes three vulnerabilities in their NVR devices.

HP Advisory - HP published an advisory that describes an improper access control vulnerability in their CCX devices.

HPE Advisory #1 - HPE published an advisory that discusses eight vulnerabilities (three with known exploits) in their Unified OSS Console Assurance Monitoring product.

HPE Advisory #2 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/ML/SY/RL/XL/Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that describes a privilege escalation vulnerability in their MSA SAN Storage VSS Provider and CAPI Proxy Software.

HPE Advisory #4 - HPE published an advisory that describes an unauthorized access to files vulnerability in their NonStop Web ViewPoint Enterprise software.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses eight third-party vulnerabilities that could be associated with their Prisma SD-WAN ION product.

Philips Advisory - Philips published an advisory that discusses a use-after-free vulnerability in multiple Philips products.

VMware Advisory - VMware published an advisory that describes three vulnerabilities in their SD-WAN Edge and SD-WAN Orchestrator products.

Updates

Eaton Update - Eaton published an update for their Apache Log4j advisory that was originally published on December 14th, 2021 and most recently updated on January 31st, 2022.

HP Update #1 - HP published an update for their OfficeJet Pro advisory that was originally published on March 20th, 2024.

HP Update #2 - HP published an update for their AMD Graphics Driver advisory that was originally published on November 21st, 2023.

HPE Update - HPE published an update for their SimpliVity Servers advisory that was originally published on February 15th, 2024.

Researcher Reports

Open Automation Software Reports - Talos published four reports for individual vulnerabilities in the OAS Platform product.

Positron Report - Zero Science published a report about an authentication bypass vulnerability in the Positron TRA7005 series broadcast signal processor.

Exploits

Petrol Pump Exploit - Sandeep Vishwakarma published an exploit for a file upload vulnerability in the Petrol Pump Management software.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-671 - subscription required. 

Saturday, March 9, 2024

Review – Public ICS Disclosures – Week of 3-2-24

This week we have 12 vendor disclosures from Aruba Networks, Commend, Moxa, Omron, QNAP (5), SEL, VMware (2), and Western Digital. There are four vendor updates from Cisco and HP (3). We also have three researcher reports of vulnerabilities for products from Lenovo. Finally, we have five exploits for Petrol Pump (3), RAD, and Solar-Log.

Advisories

Aruba Advisory - Aruba published an advisory that describes seven vulnerabilities in their ArubaOS products.

Commend Advisory - Commend published an advisory that describes three vulnerabilities in their WS-TM monitor firmware.

Moxa Advisory - Moxa published an advisory that describes a stack-based buffer overflow vulnerability in their NPort W2150A/W2250A Series web server.

Omron Advisory - Omron published an advisory that describes a path traversal vulnerability in their NJ/NX-series Machine

Automation Controllers.-

QNAP Advisory #1 - QNAP published an advisory that describes a path traversal vulnerability in their Photo Station product.

QNAP Advisory #2 - QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes a cross-site scripting vulnerability in their Network & Virtual Switch products.

QNAP Advisory #4 - QNAP published an advisory that discusses four vulnerabilities in their QuMagie Mobile 2.2.x for Android product.

QNAP Advisory #5 - QNAP published an advisory that describes three vulnerabilities in their QTS, QuTS hero, QuTScloud, and myQNAPcloud products.

SEL Advisory - SEL published an announcement that the latest version of their SEL-5030 acSELerator QuickSet Software addresses a number of undescribed cybersecurity issues.

VMware Advisory #1 - VMware published an advisory that describes four vulnerabilities in their ESXi, Workstation, and Fusion products.

VMware Advisory #2 - VMware published an advisory that describes a partial information disclosure vulnerability in their VMware Cloud Director product.

Western Digital Advisory - Western Digital published an advisory that describes a DLL hijacking vulnerability in their SanDisk PrivateAccess product.

Updates

Cisco Update - Cisco published an update for their cURL advisory that was originally published on October 12th, 2023 and most recently updated on February 21st, 2024.

HP Update #1 - HP published an update for their UC software advisory that was originally published on January 9th, 2024.

HP Update #2 - HP published an update for their UC software advisory that was originally published on January 8th, 2024.

HP Update #3 - HP published an update for their UC Software advisory that was originally published on January 9th, 2023 and most recently updated on February 9th, 2024.

Researcher Reports

Lenovo Report #1 - Binarly published a report describing an unsanitized arguments vulnerability in the Lenovo J1CN38WW.

Lenovo Report #2 - Binarly published a report describing an out-of-bounds write vulnerability in the Lenovo J1CN38WW.

Lenovo Report #3 - Binarly published a report describing an out-of-bounds write vulnerability in the Lenovo J1CN38WW.

Exploits

Petrol Pump Exploit #1 - Shubham Pandey published an exploit for two cross-site scripting vulnerabilities in the Petrol Pump management software.

Petrol Pump Exploit #2 - Shubham Pandey published an exploit for an SQL injection vulnerability in the Petrol Pump management software.

Petrol Pump Exploit #3 - Shubham Pandey published an exploit for a shell upload vulnerability in the Petrol Pump management software.

RAD Exploit - Branko Milicevic published an exploit for a directory traversal vulnerability in the RAD SecFlow-2 devices.

Solar-Log Exploit - Mesut Cetin published an exploit for a cross-site scripting vulnerability in the Solar-Log 200 PM+ product.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-205  - subscription required.

 
/* Use this with templates/template-twocol.html */