Showing posts with label Pilz. Show all posts
Showing posts with label Pilz. Show all posts

Sunday, April 26, 2026

Review - Public ICS Disclosures – Week of 4-18-26 – Part 2

 For Part 2 we have three additional vendor disclosures from Pilz, SEMTECH, and VEGA. There are six vendor updates from HPE, Mitsubishi (2), and Moxa (3). We also have a researcher report for vulnerabilities in products from Lantronix and Silex. Finally, we have two exploits for products from FortiGuard. 

Advisories  

Pilz Advisory - CERT-VDE published an advisory that discusses an insecure default initialization of resource vulnerability (with publicly available exploits) in the Pilz PASvisu Runtime. 

SEMTECH Advisory - SEMTECH published an advisory that describes three vulnerabilities in their LR11xx transceivers. 

VEGA Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the VEGA VEGAPULS 6X product. 

Updates  

HPE Update - HPE published an update for their Aruba Networking advisory that was originally published on January 13th, 2026, and most recently updated on January 27th, 2026. 

Mitsubishi Update #1 - Mitsubishi published an update for their MELSEC iQ-F Series advisory that was originally published on March 3rd, 2026. 

Mitsubishi Update #2 - Mitsubishi published an update for their Ethernet Function advisory that was originally published on April 25th, 2026, and most recently updated on February 3rd, 2026. 

Moxa Update #1 - Moxa published an update for their Ethernet Switch advisory that was originally published on October 23rd2025 and most recently updated on October 31st, 2025. 

Moxa Update #2 - Moxa published an update for their SSH Weak Algorithms advisory that was originally published on December 12th, 2025. 

Moxa Update #3 - Moxa published an update for their ICMP Timestamp Request advisory that was originally published on October 21st, 2025, and most recently updated on January 5th, 2026. 

Researcher Reports  

Lantronix Report - Forescout published a report that described eight vulnerabilities in the Lantronix EDS3000PS and EDS5000PS Series serial device servers. 

Silex Report Forescout published a report that describes 12 vulnerabilities in the Silex D330-AC serial device server. 

Exploits  

FortiGuard Exploit #1 - Ashraf Zaryouh published an exploit for an OS command injection vulnerability in the FortiGuard FortiSandbox product. 

FortiGuard Exploit #2 - Indoushka published an exploit for a relative path traversal vulnerability (which is listed in CISA’s KEV catalog) in the FortiGuard FortiWeb product. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-4b8 - subscription required. 

Saturday, February 7, 2026

Review – Public ICS Disclosures – Week of 1-31-26 – Part 1

This week we have a moderately busy disclosure week. For Part 1 there nine are vendor disclosures from Cisco, Delta Electronics, Eaton, ELECOM (2), HP, Moxa (2), and Pilz.

Advisories

Cisco Advisory - Cisco published an advisory that describes a use of hard-coded credentials vulnerability in their Prime Infrastructure product.

Delta Advisory - Delta published an advisory that describes a stack-based buffer overflow vulnerability in their ASDA-Soft product.

Eaton Advisory - Eaton published an advisory that describes two improper certificate validation vulnerabilities in their Network Cards products.

ELECOM Advisory #1 - JPCERT published an advisory that describes five vulnerabilities in multiple ELECOM wireless LAN routers.

ELECOM Advisory #2 - JPCERT published an advisory that describes four vulnerabilities in multiple ELECOM wireless LAN products.

HP Advisory - HP published an advisory that discusses 287 vulnerabilities in their ThinPro products.

Moxa Advisory #1 - Moxa published an advisory that describes two vulnerabilities in the industrial computers.

Moxa Advisory #2 - Moxa published an advisory that describes a reliance on security through obscurity vulnerability in their Ethernet Switches.

Pilz Advisory - CERT-VDE published an advisory that discusses four vulnerabilities in the Pilz PIT User Authentication Service.

 

For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-844 - subscription required.

Saturday, October 25, 2025

Review – Public ICS Disclosures – Week of 10-18-25

This week we have bulk vendor disclosures from Moxa (6). There are eight additional vendor disclosures from ABB, Belden, HP (3), Pilz, Sauter, and Zyxel. We also have three vendor updates from ABB (2) and HP.

Bulk Disclosures

Bulk Advisories – Moxa

CVE-2025-1679, CVE-2025-1680: Stored Cross-site Scripting (XSS) and Host Header Injection Vulnerabilities in Ethernet Switch,

Security Enhancement: Modbus/TCP Discrete Input Access,

Security Enhancement: Modbus/TCP Device Identification,

Security Enhancement: SNMP Agent Default Community Name (public),

Security Enhancement: SSH Weak MAC Algorithms Enabled, and

Security Enhancement: SSH Weak Key Exchange Algorithms Enabled.

Advisories

ABB Advisory - ABB published an advisory that describes a heap-based buffer overflow vulnerability in their Terra AC wallbox.

Belden Advisory - Belden published an advisory that discusses the Blast-RADIUS vulnerability. Belden

HP Advisory #1 - HP published an advisory that discusses an out-of-bounds read vulnerability in multiple notebook and desktop PCs.

HP Advisory #2 - HP published an advisory that discusses two vulnerabilities in multiple notebook and desktop PCs.

HP Advisory #3 - HP published an advisory that discusses an out-of-bounds write vulnerability in multiple notebook PCs.

Pilz Advisory - CERT-VDE published an advisory that discusses an integer overflow or wraparound vulnerability (with publicly available exploits) in the Pilz PASvisu Runtime product.

Sauter Advisory - CERT-VDE published an advisory that describes six vulnerabilities in the Sauter modulo 6 devices.

Zyxel Advisory - Zyxel published an advisory that describes two vulnerabilities in their ZLD firewalls.

Updates

ABB Update #1 - ABB published an update that provides additional information on the ALS-mini-S4/S8 IP advisory that was originally published on October 20th, 2025.

ABB Update #2 - ABB published an update that provides additional information on the CoreSense advisory that was originally published on April 16th, 2025, and most recently updated on October 10th, 2025.

HP Update - HP published an update that provides additional information on their AMD Transient Scheduler advisory that was originally published on July 10th, 2025, and most recently updated on August 15th, 2025.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-174 - subscription required.

Saturday, July 5, 2025

Review – Public ICS Disclosures – Week of 7-28-25 – Part 1

This week we have 11 vendor disclosures from ABB, Contec, Delta Electronics, Endress+Hauser, HP (2), HPE, ifm, and Pilz (3).

Advisories

ABB Advisory - ABB published an advisory that describes four vulnerabilities in their web UI REST Interface.

Contec Advisory - Contec published an advisory that describes two vulnerabilities in their CONPROSYS HMI System.

Delta Advisory - Delta published an advisory that describes two deserialization of untrusted data vulnerabilities in their DTM Soft products.

Endress+Hauser Advisory - CERT-VDE published an advisory that discusses 19 vulnerabilities in the Endress+Hauser MEAC300-FNADE4.

HP Advisory #1 - HP published an advisory that describes a stack-based buffer overflow vulnerability in their Universal Print Driver.

HP Advisory #2 - HP published an advisory that discusses 46 vulnerabilities in their Device Manager.

HPE Advisory - HPE published an advisory that discusses a server-side request forgery vulnerability in their Telco Service Orchestrator software.

Ifm Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the ifm Smart PLC AC4xxS.

Pilz Advisory #1 - CERT-VDE published an advisory that describes an incorrect type conversion or cast vulnerability in the Pilz IndustrialPI 4 with IndustrialPI webstatus.

Pilz Advisory #2 - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the Pilz IndustrialPI 4 with Firmware Bullseye.

Pilz Advisory #3 - CERT-VDE published an advisory that discusses an authentication bypass by primary weakness vulnerability in the Pilz Software PiCtory.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-cff - subscription required.

Saturday, February 10, 2024

Review – Public ICS Disclosure – Week of 2-3-24

This week we have 22 vendor disclosures from Badger, B&R Automation (2), FortiGuard (4), GE Vernova, Hitachi (2), HPE, Meinberg, Pilz, SEL, Sharp, VMware, WatchGuard (4), and Western Digital. There is also one update from HP. Finally, we have three exploits for products from Forta, Milesight, and Zyxel.

Advisories

Badger Advisory - Incibe-CERT published an advisory that describes four vulnerabilities in their Monitool product.

B&R Advisory #1 - B&R published an advisory that describes a use of broken or risky cryptographic algorithm in their Runtime FTP server component.

B&R Advisory #2 - B&R published an advisory that describes a cross-site scripting vulnerability in their SDM Web interface.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an out-of-bounds write vulnerability (listed in CISA’s Known Exploit Exploits Catalog) in their FortiOS.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes a lack of certificate validation vulnerability in their FortiOS.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a use of externally-controlled format string vulnerability.

FortiGuard Advisory #4 - FortiGuard published an advisory that discusses an uncontrolled resource consumption vulnerability (which is listed in CISA’s KEV) in their FortiOS and FortiProxy products.

GE Advisory - GE published an advisory that discusses a use of externally controlled format string vulnerability in their NetworkST4 and Remote Operations Offering.

Hitachi Advisory #1 - Hitachi published an advisory that discusses ten vulnerabilities in multiple Hitachi products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses two vulnerabilities in their JP1 product.

HPE Advisory - HPE published an advisory that discusses 17 vulnerabilities in their Unified OSS Console Assurance Monitoring (UOCAM).  

Meinberg Advisory - Meinberg published an advisory that discusses 18 vulnerabilities in their LANTIME-Firmware.

Pilz Advisory - Pilz published an advisory that discusses six vulnerabilities.

SEL Advisory - SEL published an update notice for a new version of their SEL-5025 Secure Port Software which fixes two security issues.

Sharp Advisory - Sharp published an advisory that describes a path traversal vulnerability in multiple Sharp public display products.

VMware Advisory - VMware has published an advisory that describes five vulnerabilities in their VMware Aria Operations for Networks product.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes a memory corruption vulnerability in their Endpoint products.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes an out-of-bounds write vulnerability in their Endpoint products.

WatchGuard Advisory #3 - WatchGuard published an advisory that describes an arbitrary kernel read vulnerability in their Endpoint products.

WatchGuard Advisory #4 - WatchGuard published an advisory that discusses four Ivanti vulnerabilities.

Western Digital Advisory - Western Digital published an advisory that describes two vulnerabilities in their My Cloud, WD Cloud, and SanDisk ibi products.

Updates

HP Update - HP published an update for their UC Software advisory that was originally published on January 9th, 2024.

Exploits

Forta Exploit - James Horseman published an Metasploit module for a forced browsing vulnerability in the Forta GoAnywhere MFT.

Zyxel Exploit - Marco Ivaldi published an exploit for an improper input validation vulnerability in multiple Zyxel products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-2-3 - subscription required.

Saturday, February 3, 2024

Review – Public ICS Disclosures – Week of 1-27-24 – Part 1

This week we have 24 vendor disclosures from Festo, Hitachi (6), Hitachi Energy (3), Honeywell, Pilz, and QNAP (12).

Advisories

Festo Advisory - CERT-VDE published an advisory that discusses 16 vulnerabilities in the multiple Festo products.

Hitachi Advisory #1 - Hitachi published an advisory that discusses seven undescribed vulnerabilities in their Cosminexus Developer's Kit for Java(TM) and Hitachi Developer's Kit for Java.

Hitachi Advisory #2 - Hitachi published an advisory that discusses 11 vulnerabilities in their Ops Center Analyzer.

Hitachi Advisory #3 - Hitachi published an advisory that discusses three vulnerabilities in their Ops Center Administrator product, one of which is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Hitachi Advisory #4 - Hitachi published an advisory that describes an incorrect default permissions vulnerability in their Hitachi Storage Plug-in for VMware vCenter.

Hitachi Advisory #5 - Hitachi published an advisory that discusses four vulnerabilities in their Command Suite products one of which is listed in CISA’s KEV catalog.

Hitachi Advisory #6 - Hitachi published an advisory that discusses 27 vulnerabilities in their Disk Array Systems products.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that discusses an improper input validation vulnerability in their TropOS core routers.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses three vulnerabilities in their MSM Product.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that discusses nine vulnerabilities in their AFF660/665 series products.

Honeywell Advisory - Honeywell published an advisory for two vulnerabilities in a number of their smartcard readers/cards.

Pilz Advisory - CERT-VDE published an advisory that describes two cross-site scripting vulnerabilities in the Pilz PASvisu and PMI v8xx products.

QNAP Advisory #1 - QNAP published an advisory that describes two vulnerabilities in their Photo Station product. The vulnerabilities were reported by lebr0nli.

QNAP Advisory #2 - QNAP published an advisory that describes an unchecked return value vulnerability in their QTS and QuTS hero products.

QNAP Advisory #3 - QNAP published an advisory that discusses an improper validation of integrity check value vulnerability in their QTS and QuTS hero products.

QNAP Advisory #4 - QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #5 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #6 - QNAP published an advisory that describes three vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #7 - QNAP published an advisory that describes three OS command injection vulnerabilities in their QTS, QuTS hero and QuTScloud products.

QNAP Advisory #8 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero and QuTScloud products.

QNAP Advisory #9 - QNAP published an advisory that describes an OS command injection vulnerability in their TS, QuTS hero and QuTScloud products.

QNAP Advisory #10 - QNAP published an advisory that describes a classic buffer overflow vulnerability in their QTS, QuTS hero and QuTScloud products.

QNAP Advisory #11 - QNAP published an advisory that describes eight vulnerabilities in their QTS, QuTS hero and QuTScloud products.

QNAP Advisory #12 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero and QuTScloud.

 

For more information about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-76f - subscription required.

Saturday, December 9, 2023

Review – Public ICS Disclosures – Week of 12-2-23

This week we have 37 vendor disclosures from CODESYS, Dell (2), HP, HPE, Insyde, Pilz (3), QNAP (3), SEL (2), Siemens, Tanzu (20), and Wago (2). There are three vendor updates from Atos, CODESYS, and Dell. We have two researcher reports for vulnerabilities in products from Atos and R Radio Network. Finally, we have two exploits for products from FortiGuard and Orpak.

Advisories

CODESYS Advisory - CODESYS published an advisory that describes an OS command injection vulnerability in their Control runtimes running on Linux or QNX operating systems.

Dell Advisory #1 - Dell published an advisory that discusses an out-of-bounds write vulnerability in the ThisOS.

Dell Advisory #2 - Dell published an advisory that discusses 28 vulnerabilities in their Dell Wyse Management Suite.

HP Advisory - HP published an advisory that discusses an improper input validation vulnerability in multiple notebook and desktop computers.

HPE Advisory - HPE published an advisory that describes an information disclosure vulnerability in their HP-UX System Management Homepage.

Insyde Advisory - Insyde published an advisory that discusses an improper input validation vulnerability in multiple kernels

Pilz Advisory #1 - CERT-VDE published an advisory that discusses two vulnerabilities in the Pilz PASvisu and PMI products.

Pilz Advisory #2 - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in the Pilz PASvisu, PIT Transponder Manager, and PMI products.

Pilz Advisory #3 - Pilz published an advisory that discusses vulnerabilities in multiple products.

QNAP Advisory #1 - QNAP published an advisory that describes a cross-site scripting vulnerability in their QTS and QuTS hero products.

QNAP Advisory #2 - QNAP published an advisory that describes an OS command injection vulnerability in their legacy VioStor NVR product.

QNAP Advisory #3 - QNAP published an advisory that describes two classic buffer overflow vulnerabilities in their QTS and QuTS hero products.

QNAP Advisory #4 - QNAP published an advisory that discusses five vulnerabilities in their QTS and QuTS hero products.

SEL Advisories - SEL announced new versions of two products that address cybersecurity issues.

Siemens Advisory - Siemens discussed a Black Hat Europe presentation describing the details of the legacy PG/PC and HMI communication protocol as used between TIA Portal / HMIs and SIMATIC S7-1500 SW Controller in versions before V17.

Tanzu Advisories - Tanzu published 20 advisories discussing third-party vulnerabilities in various Tanzu products.

Wago Advisory #1 - CERT-VDE published an advisory that describes an observable discrepancy vulnerability in the Wago Smart Designer product.

Wago Advisory #2 - CERT-VDE published an advisory that describes an improper input validation vulnerability in the Wago Telecontrol Configurator and WagoAppRTU products.

Updates

Atos Update - Atos published an update for their Unify OpenScape advisory that was originally published on October 4th, 2023 and most recently updated on September 10th, 2023.

CODESYS Update - CODESYS published an update for their WIBU CodeMeter Runtime advisory that was originally published on August 17th, 2023 and most recently updated on October 31st, 2023.

Dell Update - Dell published an update for their Rugged Control Center advisory that was originally published on November 30th, 2023.

Researcher Reports

Atos Report - SEC Consult published a report that describes an argument injection vulnerability in the Atos Unify OpenScape products.

R Radio Network Report - Zero Science published a report describing two vulnerabilities in the R Radio Network.

Exploits

FortiGuard Exploit - Cody Sixteen published an exploit for a post authentication CLI crash vulnerability in the FortiWeb VM product.

Orpak Exploit - Parsa Rezaei Khiabanloo published an exploit for a default password vulnerability in the Orpak fueling systems.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-66a - subscription required.

Saturday, October 14, 2023

Review – Public ICS Disclosures – Week of 10-7-23 – Part 1

This week we have 19 vendor disclosures from Cisco, FortiGuard (5), Insyde, Palo Alto Networks (3), Pilz, QNAP (4), Rockwell Automation, Sick, Synology, and Zebra Technologies. There is a vendor update from Cisco. Finally, for Part 1 anyway, we have 22 researcher reports for products from Peplink (4), SoftEther (9), and Yifan (9).

For Part 2 we will have disclosures and updates from Schneider and Siemens and five control system exploits.

Advisories

Cisco Advisory - Cisco published an advisory that discusses the recently announced SOCKS5 handshake vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an access control vulnerability in their FortiOS products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an information disclosure vulnerability in their FortiOS products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes an improper authorization vulnerability in their FortOS products.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiOS products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes a use after free vulnerability in their FortiOS and FortiProxy products.

Insyde Advisory - Insyde published an advisory that describes an incorrect information reporting vulnerability in their TrEEConfigDriver.

Palo Alto Networks Advisory # 1 - Palo Alto Networks published an advisory that discusses the Rapid Reset vulnerability.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a clear-text storage of sensitive information vulnerability in their Cortex XSOAR product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that discusses the announced SOCKS5 handshake vulnerability.

Pilz Advisory - CERT VDE published an advisory that discusses two vulnerabilities in multiple Pilz products.

QNAP Advisory #1 - QNAP published an advisory that describes three vulnerabilities in their Video Station product.

QNAP Advisory #2 - QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes a path traversal vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #4 - QNAP published an advisory that describes an OS command injection vulnerability in their Container Station product.

Rockwell Advisory - Rockwell published an advisory that describes an improper input validation vulnerability in their FactoryTalk Linx product.

Sick Advisory - Sick published an advisory that describes nine vulnerabilities in their Application Processing Unit.

Synology Advisory - Synology published an advisory that discusses the Rapid Reset Vulnerability.

Zebra Advisory - INCIBE CERT published an advisory that describes an authentication bypass using an alternate path or channel in the Zebra  ZTC ZT410-203dpi ZPL printers.

Updates

Cisco Update - Cisco published an update for their Adaptive Security Appliance Software advisory that was originally published on September 6th, 2023, and most recently updated on September 29th, 2023.

Researcher Reports

Peplink Reports - Cisco Talos published four reports about vulnerabilities in the Peplink Surf SOHO HW1 routers.

SoftEther Reports - CISCO Talos published 9 reports on vulnerabilities in the VPN product from SoftEther.

Yifan Reports - Cisco Talos published nine reports about vulnerabilities in the Yifan YF325 industrial cellular router.

 

For more details about these disclosures, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-a73 - subscription required.

 
/* Use this with templates/template-twocol.html */