Showing posts with label Public ICS Disclosure. Show all posts
Showing posts with label Public ICS Disclosure. Show all posts

Monday, June 15, 2026

Review - Public ICS Disclosures – Week of 6-6-26 – Part 3

For Part 3 we have three additional vendor disclosures from Genetec (2) and VMware. There are bulk vendor updates from HP (5) and Siemens (10). There are four additional vendor updates from ABB, FortiGuard, Mitsubishi, and Moxa. We also have three researcher reports for vulnerabilities in products from Trane, Vertiv, and Splunk. Finally, we have four exploits for products from Palo Alto Networks (2), FortiGuard, and WatchGuard. 

Advisories  

Genetec Advisory #1 - Genetec published an advisory that describes an incorrect permission assignment for critical resource vulnerability in Genetec product installations deploying RabbitMQ. 

Genetec Advisory #2 - Genetec published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Security Center main server installations. 

VMware Advisory - Broadcom published an advisory that describes three cross-site scripting vulnerabilities in the VMware Cloud Foundation Operations product. 

Bulk Vendor Updates  

HP (5) 

Siemens (10) 

Updates  

ABB Update - ABB published an update for their Freelance Security Lock advisory that was originally published on November 9th, 2025. 

FortiGuard Update FortiGuard published an update for their Sensitive 2FA Information advisory that was originally published on October 14th, 2025. 

Mitsubishi Update - Mitsubishi published an update for their Realtek Chips advisory that was originally published on March 24th, 2026. 

Moxa Update - Moxa published an update for their Diffie-Hellman Key Exchange Protocol advisory that was originally published on June 2nd, 2025. 

Researcher Reports  

Trane Report - Claroty published a report that describes five vulnerabilities in the Trane Tracer SC+ HVAC controller. 

Vertiv Report Claroty published a report that describes two vulnerabilities in the Vertiv’s Liebert IS-UNITY-DP network cards. 

Splunk Report WatchTowr published a report that describes a missing authentication for critical function vulnerability in the PostgreSQL Sidecar Service Endpoint in Splunk Enterprise. 

Exploits  

Palo Alto Networks Exploit #1 - Indoushka published a Metasploit module for a reliance on cookies without validation and integrity checking vulnerability in the PAN GlobalProtect product. 

Palo Alto Networks Exploit #2 - Gray Xploit published an exploit for a reliance on cookies without validation and integrity checking vulnerability in the PAN GlobalProtect product. 

FortiGuard Exploit Indoushka published a Metasploit module for an OS command injection vulnerability in the FortiGuard FortiSandbox product. 

WatchGuard Exploit - Cody Sixteen published an exploit for a logic error vulnerability in the WatchGuard Firebox product. 


For additional information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-81a - subscription required. 

Saturday, August 31, 2024

Review – Public ICS Disclosures – Week of 8-24-24

This week we have 21 vendor advisories from Beckhoff (4), B&R, Dassault Systèmes (4), Elecom (2), Hitachi, Hitachi Energy, HP (2), Meinberg, Panasonic, TRUMPF (2), and Wireshark. There are also eight vendor updates from B&R, Dell, Elecom (5), and Moxa. Finally, we have five exploits for products from Aruba and Elber (4).

Advisories

Beckhoff Advisory #1 - CERT-VDE published an advisory that describes a cross-site scripting vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #2 - CERT-VDE published an advisory that describes an authentication bypass by alternate path or channel vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #3 - CERT-VDE published an advisory that describes a classic buffer overflow vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #4 - CERT-VDE published an advisory that describes an allocation of resources without limit or throttling vulnerability in the Beckhoff TwinCAT/BSD-based products.

B&R Advisory - B&R published an advisory that describes three vulnerabilities in their  APROL condition monitoring software.

Dassault Systèmes  Advisory #1 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their ENOVIA Collaborative Industry Innovator.

Dassault Systèmes  Advisory #2 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DSwym in 3DSwymer.

Dassault Systèmes  Advisory #3 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DDashboard in 3DSwymer.

Dassault Systèmes  Advisory #4 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DDashboard in 3DSwymer.

Elecom Advisory #1 - JP-CERT published an advisory that describes four vulnerabilities in the Elecom wireless LAN routers and access points.

Elecom Advisory #2 - JP-CERT published an advisory that describes three vulnerabilities in the Elecom wireless LAN routers.

Hitachi Advisory - Hitachi published an advisory that describes an authentication bypass vulnerability in their Ops Center Common Services product.

Hitachi Energy Advisory - Hitachi Energy published an advisory that describes an SQL injection vulnerability in their MicroSCADA X SYS600 product.

HP Advisory #1 - HP published an advisory that discusses two vulnerabilities in their Z4, Z6, and Z8 workstations.

HP Advisory #2 - HP published an advisory that discusses an incorrect default permissions vulnerability in their notebook PC’s.

Meinberg Advisory - Meinberg published an advisory that discusses three vulnerabilities (all with publicly available exploits) in their LANTIME product.

Panasonic Advisory - JP-CERT published an advisory that describes a stack-based buffer overflow vulnerability in the Panasonic Control FPWIN Pro7.

Trumpf Advisory #1 - CERT-VDE published an advisory that discusses the regreSSHion vulnerability.

Trumpf Advisory #2 - CERT-VDE published an advisory that discusses a use after free vulnerability (listed in the CISA Known Exploited Vulnerability Catalog) in the Trumpf TruControl laser control software products.

Wireshark Advisory - Wireshark published an advisory that describes an out-of-bounds read vulnerability in their NTLMSSP dissector.

Updates

B&R Updates - B&R published an update for their Automation Runtime advisory that was originally published on August 9th, 2024.

Dell Update - Dell published an update for their Dell ThinOS advisory that was originally published on June 12th, 2024, and most recently updated on July 19th, 2024.

Elecom Update #1 - JP-CERT published an update for their ELECOM and LOGITEC network devices advisory that was originally published on August 10th, 2024.

Elecom Update #2 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on July 30th, 2024.

Elecom Update #3 - JP-CERT published an update for their wireless LAN routers and wireless LAN repeater advisory that was originally published on March 26th, 2024 and most recently updated on May 28th, 2024.

Elecom Update #4 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on March 26th, 2024 and most recently updated on May 28th, 2024.

Elecom Update #5 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on May 28th, 2024.

Moxa Update - Moxa published an update for their regreSSHion advisory that was originally published on August 2nd, 2024, and most recently updated on August 9th, 2024.

Exploits

Aruba Exploit - Hosein Vita published an exploit for a remote code execution vulnerability in the Aruba 501 CN12G5W0XX wireless access point.

Elber Exploit #1 - LiquidWorm published an exploit for an authentication bypass vulnerability in the Elber ESE DVB-S/S2 Satellite Receiver.

Elber Exploit #2 - LiquidWorm published an exploit for a device configuration vulnerability in the Elber ESE DVB-S/S2 Satellite Receiver.

Elber Exploit #3 - LiquidWorm published an exploit for an authentication bypass vulnerability in the Elber Wayber Analog/Digital Audio.

Elber Exploit #4 - LiquidWorm published an exploit for a device configuration vulnerability in the Elber Wayber Analog/Digital Audio.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, as well as a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-631 - subscription required.

Saturday, June 29, 2024

Review – Public ICS Disclosures – Week of 6-22-24 – Part 1

This week we have 18 vendor disclosures from ABB, Hitachi (3), Hitachi Energy, Honeywell, HP (5), HPE, Moxa, Rockwell, and VMware (3).

Advisories

ABB Advisory - ABB published an advisory that discusses an untrusted search path vulnerability in their PCM600 Installer product.

Hitachi Advisory #1 - Hitachi published an advisory that discusses two vulnerabilities in their Storage Provider for VMware vCenter product.

Hitachi Advisory #2 - Hitachi published an advisory that describes an incorrect default permissions vulnerability in their Storage Provider for VMware vCenter.

Hitachi Advisory #3 - Hitachi published an advisory that discusses 36 vulnerabilities in their Disk Array products.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses four vulnerabilities in their AFS/AFR series products.

Honeywell Advisory - Honeywell published an advisory that discusses an uncontrolled search path vulnerability in their MAXPRO NVR Computer.

HP Advisory #1 - HP published an advisory that discusses the Zenbleed vulnerability in their AMD Client UEFI.

HP Advisory #2 - HP published an advisory that describes a TOCTOU vulnerability in their PC Bios products.

HP Advisory #3 - HP published an advisory that describes three vulnerabilities in multiple HP PC products.

HP Advisory #4 - HP published an advisory that discusses the LogoFAIL vulnerabilities in multiple PC Bios products.

HP Advisory #5 - HP published an advisory that discusses an uncontrolled search path element vulnerability in multiple HP PC products.

HPE Advisory #1 - HPE published an advisory that discusses ten vulnerabilities in their ProLiant DL/XL Servers and Cray Supercomputer products.

HPE Advisory #2 - HPE published an advisory that describes a code injection vulnerability in their Athonet Mobile Core.

Moxa Advisory - Moxa published an advisory that describes three vulnerabilities in their EDS-405A/408A Series products.

Rockwell Advisory - Rockwell published an advisory that describes three improper input validation vulnerabilities in their ThinManager ThinServer product.

VMware Advisory #1 - Broadcom published an advisory that describes three vulnerabilities in their ESXi and vCenter Server products.

VMware Advisory #2 - Broadcom published an advisory that describes an improper privilege management vulnerability in their Cloud Director product.

VMware Advisory #3 - Broadcom published an advisory that describes an insertion of sensitive information vulnerability in their Cloud Director Object Storage Extension.

 

For more information on these disclosures, including 3rd party reports, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-601 - subscription required.

Saturday, March 23, 2024

Review – Public ICS Disclosures – Week of 3-16-24

This week we have eight vendor disclosures from Belden, Bosch, Buffalo Tech, Honeywell, HP, Planet Technology, and Rockwell (2). There are five vendor updates from Eaton, HP (2), Palo Alto Networks, and QNAP. We have two researcher reports for vulnerabilities in products from FortiGuard and Unitronics. Finally, we have four exploits for products from APC and TELSAT (3).

Advisories

Belden Advisory - Belden published an advisory that discusses five vulnerabilities in multiple Hirschmann products.

Bosch Advisory - Bosch published an advisory that describes a command injection vulnerability in their Network Synchronizer.

Buffalo Advisory - JP-CERT published an advisory that describes an insufficient data validation vulnerability in the Buffalo LinkStation 200 series NAS.

Honeywell Advisory - Honeywell published an advisory that describes a cross-site scripting vulnerability in their MPA2 Web Application.

HP Advisory - HP published an advisory that describes a denial of service vulnerability in their OfficeJet Pro printers.

Planet Advisory - Incibe-CERT published an advisory that describes three vulnerabilities in the Planet IGS-4215-16T2S industrial ethernet switch.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper security protection for remote restart action vulnerability in their FactoryTalk® View ME on PanelView.

Rockwell Advisory #2 - Rockwell published an advisory that describes three vulnerabilities in their PowerFlex® 527 product.

UPDATES

Eaton Update - Eaton published an update for their User Management System advisory that was originally published on November 24th, 2023 and most recently updated on December 20th, 2023.

HP Update #1 - HP published an update for their Intel 2023.4 IPU advisory that was originally published on December 11th, 2023 and most recently updated January 9th, 2024.

HP Update #2 - HP published an update for their AMD Client UEFI firmware advisory that was originally published on December 7th, 2023 and most recently updated on January 5th, 2024.

Researcher Reports

FortiGuard Report - Horizon3 published a report describing an SQL injection vulnerability in the FortiGuard FortiClient EMS product.

Unitronics Report - Claroty published a report describing eight vulnerabilities in the Unitronics UniStream integrated PLC/HMI products.

Exploits

APC Exploit - Victor Garcia published an exploit for a path traversal vulnerability in the APC UPS Network Management Card.

TELSAT Exploits - LIQUIDWORM published exploits for three vulnerabilities in the TELSAT marKoni FM Transmitter.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-051 - subscription required.

Saturday, January 6, 2024

Review – Public ICS Disclosures – Week of 12-30-23

This week we have 15 vendor disclosures from HPE (2), QNAP (8), and Wireshark (5). There are also six vendor updates from Dell, HP (4), and Moxa. Finally, we have five researcher reports for products from Inductive Automation.

Advisories

HPE Advisory #1 - HPE published an advisory that discusses five vulnerabilities in their ProLiant RL300 Gen11 Servers.

HPE Advisory #2 - HEP published an advisory that discusses four vulnerabilities in their Unified OSS Console Assurance Monitoring (UOCAM) product. One of the vulnerabilities is listed on CISA’s Known Exploited Vulnerability (KEV) catalog.

QNAP Advisory #1 - QNAP published an advisory that describes six classic buffer overflow vulnerabilities in their QTS and QuTS hero products.

QNAP Advisory #2 - QNAP published an advisory that describes a heap-based buffer overflow vulnerability in their Netatalk product.

QNAP Advisory #3 - QNAP published an advisory that describes two vulnerabilities in their Video Station product.

QNAP Advisory #4 - QNAP published an advisory that describes an SQL injection vulnerability in their QuMagie product.

QNAP Advisory #5 - QNAP published an advisory that describes two vulnerabilities in their QuMagie product.

QNAP Advisory #6 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS and QuTS hero products.

QNAP Advisory #7 - QNAP published an advisory that describes a prototype pollution vulnerability in their QTS and QuTS hero products.

QNAP Advisory #8 - QNAP published an advisory that describes an OS command injection vulnerability in their QcalAgent.

Wireshark Advisory #1 - Wireshark published an advisory that describes an uncontrolled recursion vulnerability in their GVCP dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes a NULL pointer dereference vulnerability in their IEEE 1609.2 dissector.

Wireshark Advisory #3 - Wireshark published an advisory that describes an out-of-bounds read vulnerability in their HTTP3 dissector.

Wireshark Advisory #4 - Wireshark published an advisory that describes an uncontrolled recursion vulnerability in their Zigbee TLV dissector.

Wireshark Advisory #5 - Wireshark published an advisory that describes an uncontrolled recursion vulnerability in their DOCSIS dissector.

Updates

Dell Update - Dell published an update for their Apache Log4j advisory that was originally published in December 2021 and most recently updated on December 14th, 2022.

HP Update #1 - HP published an update for their Intel Virtual RAID advisory that was originally published on November 20th, 2023.

HP Update #2 - HP published an update for their Intel Dynamic Tuning Technology Software that was originally published on November 6th, 2023.

HP Update #3 - HP published an update for their AMD Client UEFI Firmware advisory that was originally published on December 7th, 2023.

HP Update #4 - HP published an update for their HP PC BIOS advisory that was originally published on September 5th, 2023 and most recently updated on November 2nd, 2023.

Researcher Reports

Inductive Automation Reports - The Zero Day Initiative published five reports describing individual vulnerabilities in the Inductive Automation Ignition product.

 

For more details about these disclosures, including links to 3rd party advisories and researcher reports as well as brief summaries of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-5ae - subscription required.

Saturday, December 2, 2023

Review – Public ICS Disclosures – Week of 11-25-23

This week we have 15 vendor disclosures from Festo, Hitachi Energy (3), HPE, Medtronic, Red Lion, Ruckus, SEL, Sierra Wireless, Synology (2), WatchGuard, and Zyxel (2). There are nine vendor updates from Hitachi Energy (7), HPE, and VMware. There is also a researcher report describing vulnerabilities in products from SEL. Finally, we have two exploits for products from Loytec.

Advisories

Festo Advisory - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in multiple Festo products.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes three vulnerabilities in their RTU500 series products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses an off-by-one error vulnerability in their SDM600 series products.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that describes an improper input validation vulnerability in their s Relion® 670/650/SAM600-IO series products.

HPE Advisory - HPE published an advisory that discusses two improper initialization vulnerabilities in their Cray Servers and ProLiant DL/XL Servers.

Medtronic Advisory - Medtronic published an advisory that discusses two vulnerabilities in their Mainspring Data Express, and Vital Sync Virtual Patient Monitoring Platform products.

Red Lion Advisory - Red Lion published an advisory that describes an improper neutralization of special elements vulnerability in their Crimson 3.2 software.

Ruckus Advisory - Ruckus published an advisory that describes a cross-site scripting vulnerability in multiple Ruckus products.

SEL Advisory - SEL published a cybersecurity notice for their Blueframe OS product.

Sierra Wireless Advisory - Sierra Wireless published an advisory that describes eight vulnerabilities in their ALEOS, the operating system used in certain Sierra Wireless AirLink Routers.

Synology Advisory #1 - Synology published an advisory that describes an arbitrary code execution vulnerability in their Synology Camera BC500 and Synology Camera TC500.

Synology Advisory #2 - Synology published an advisory that describes a man-in-the-middle vulnerability in their Router Manager.

WatchGuard Advisory - WatchGuard published an advisory that discusses the heap buffer overflow in libwebp WebP Codec vulnerability that is listed in the CISA Known Exploited Vulnerabilities catalog.

Zyxel Advisory #1 - Zyxel published an advisory that describes nine vulnerabilities in multiple Zyxel firewall and access point (AP) products.

Zyxel Advisory #2 - Zyxel published an advisory that describes the six vulnerabilities in their NAS326 and NAS542 products.

Updates

Hitachi Energy Updates - Hitachi Energy published seven updates for the purpose of rebranding the advisories from “Hitachi/ABB Power Grids” to “Hitachi Energy”.

HPE Update - HPE published an update for their OneView advisory that was originally published on October 25th, 2023.

VMware Update - VMware published an update for their Cloud Director Appliance advisory that was originally published on November 14th, 2023.

Researcher Reports

SEL Report - Nozomi Networks published a report describing five vulnerabilities in the SEL-451 substation bay control  device.

Exploits

Loytec Exploit #1 - Chizuru Toyama published an exploit for three vulnerabilities in the Loytec LINX Configurator.

Loytec Exploit #2 - Chizuru Toyama published an exploit for a four vulnerabilities in the Loytec LINX Configurator.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-7e2 - subscription required.

Saturday, November 25, 2023

Review – Public ICS Disclosures – Week of 11-18-23 – Part 2

For Part 2 we have seven more vendor disclosures from Mitsubishi, Philips, Phoenix Contact, Western Digital, WAGO (2), and Zyxel. There are also three updates from Hitachi Energy, HP, HPE. Finally, we have seven researcher reports about vulnerabilities in products from Thales (7).

Advisories

Mitsubishi Advisory - Mitsubishi published an advisory that describes two improper input validation vulnerabilities in their GX Works2 product.

Philips Advisory - Philips published an advisory that discusses the F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability that is listed on the CISA Known Exploited Vulnerability Catalog.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses two vulnerabilities in products using the WIBU CodeMeter Runtime product.

Western Digital Advisory - Western Digital published an advisory that describes multiple uncontrolled search path element vulnerabilities (single CVE) in their SanDisk Security Installer for Windows product.

WAGO Advisory #1 - CERT-VDE published an advisory that describes an improper privilege management vulnerability in multiple WAGO products.

WAGO Advisory #2 - CERT-VDE published an advisory that describes an OS command injection vulnerability in WAGO managed switches.

Zyxel Advisory - Zyxel published an advisory that describes an out-of-bounds write vulnerability in their SecuExtender SSL VPN Client software.

Updates

Hitachi Energy Update - Hitachi Energy published an update for their Apache ActiveMQ advisory that was originally published on November 14th, 2023.

HP Update - HP published an update for their PROSet/Wireless WiFi and Killer™ WiFi advisory that was originally published on August 8th, 2023, and most recently updated on September 12th, 2023.

HPE Update - HPE published an update for their IceWall products advisory that was originally published on June 20th, 2023 and most recently updated on July 24th, 2023.

Researcher Reports

Thales Reports - Kaspersky published seven reports about individual vulnerabilities in the Thales Telit Cinterion products.

 

For more information on these disclosures, including links to 3rd party advisories and brief descriptions of changes in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-cec - subscription required.

 
/* Use this with templates/template-twocol.html */