Showing posts with label Riello. Show all posts
Showing posts with label Riello. Show all posts

Saturday, September 21, 2024

Review – Public ICS Disclosures – Week of 9-14-24

This week we have 16 vendor disclosures from CIRCUTOR, Dell, Dassault Systems (2), GE Vernova, Hitachi, HP (2), Moxa, Philips (3), SEL, Softing, Supermicro, and VMware. There are also two updates from HPE and Moxa. Finally, we also have six researcher reports for products from OpenPLC (3), Riello, and Supermicro (2).

Advisories

CIRCUTOR Advisory - Incibe-CERT published an advisory that describes six vulnerabilities in the CIRCUTOR Q-SMT and TCP2RS+ substation equipment.

Dell Advisory - Dell published an advisory that discusses seven vulnerabilities (three with publicly available exploits) in their ThinOS products.

Dassault Systems Advisory #1 - Dassault Systems published an advisory that describes a cross-site scripting vulnerability in their 3DEXPERIENCE product.

Dassault Systems Advisory #2 - Dassault Systems published an advisory that describes a cross-site scripting vulnerability in their 3DEXPERIENCE product.

GE Vernova Advisory - GE Vernova published an advisory that describes six vulnerabilities in their ControlST platform.

HPE Advisory #1 - HPE published an advisory that discusses five vulnerabilities in their StoreEasy Servers.

HPE Advisory #2 - HPE published an advisory that describes three vulnerabilities in their Aruba Networking Controller and Gateway-Based AOS.

Moxa Advisory - Moxa published an advisory that describes three vulnerabilities in their MXview One and MXview One Central Manager Series.

Philips Advisory #1 - Philips published an advisory that discusses the recent Fortinet breach.

Philips Advisory #2 - Philips published an advisory that discusses the recent VMware vulnerabilities.

Philips Advisory #3 - Philips published an advisory that discusses the recent Windows Update Downgrade Attack Advisory.

SEL Advisory - SEL published a version update notice for their SEL-5032 acSELerator Architect Software.

Softing Advisory - Softing published an advisory that describes a missing release of memory vulnerability in their uaToolkit Embedded and smartLink products.

Supermicro Advisory - Supermicro published an advisory that discusses two vulnerabilities in their Denverton platform.

VMware Advisory - VMware published an advisory that describes two vulnerabilities in their vCenter Server.

Updates

HPE Update - HPE published an update for their HPE ProLiant DL/ML/XL, Synergy, and Edgeline Servers advisory that was originally published on September 16th, 2024.

Moxa Update - Moxa published an update for their  regreSSHion vulnerability advisory that was originally published on August 2nd, 2024 and most recently updated on September 10th, 2024.

Researcher Reports

OpenPLC Report #1 - Talos published a report that describes a stack-based buffer overflow vulnerability in the OpenPLC OpenPLC _v3.

OpenPLC Report #2 - Talos published a report that describes two out-of-bounds read vulnerabilities in the OpenPLC OpenPLC _v3.

OpenPLC Report #3 - Talos published a report that describes two incorrect type or cast vulnerabilities in the OpenPLC OpenPLC _v3.

Riello Report - CyberDanube published a report describing two vulnerabilities in the Riello Netman 204 network communications card.

Supermicro Report #1 - Binarly published a report that describes a use of hard-coded credentials vulnerability in the Supermicro BMC Firmware.

Supermicro Report #2 - Binarly published a report that describes an insecure RSA signing key used in multiple Supermicro servers.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-ed6 - subscription required.

Saturday, June 17, 2023

Review – Public ICS Disclosures – Week of 6-10-23 – Part 1

This week we have thirteen vendor disclosures from Carrier, HPE (2), Insyde (3), Palo Alto Networks (3), Phoenix Contact, QNAP, Riello, and VMware. There is also an update from HPE.

In Part 2, I will look at advisories and updates for products from FortiGuard, Schneider and Siemens.

Advisories

Carrier Advisory - Carrier published an advisory that describes an authorization bypass vulnerability in their g MASmobile Classic application.

HPE Advisory #1 - HPE published an advisory that describes a privileged information disclosure vulnerability in their Insight Remote Support (I-RS) product.

HPE Advisory #2 - HPE published an advisory that discusses 19 vulnerabilities in their Integrity MC990 X Server RMC firmware.

Insyde Advisory #1 - Insyde published an advisory that describes a memory leak vulnerability in their CapsuleIFWUSmm driver.

Insyde Advisory #2 - Insyde published an advisory that discusses an empty TPM platform authorization vulnerability.

Insyde Advisory #3 - Insyde published an advisory that describes a security boundary bypass vulnerability in the InsydeH2O UEFI.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a cross-site scripting vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a privilege escalation vulnerability in their GlobalProtect App.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that discusses the MOVEit Vulnerabilities.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses two vulnerabilities in their FL MGUARD family.

QNAP Advisory - QNAP published an advisory that discusses four vulnerabilities in multiple products.

Riello Advisory - Incibe-CERT published an advisory that describes a CSRF token validation vulnerability in the Riello UPS Netman-204 network adapter.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their Tools product.

Updates

HPE Update - HPE published an update for their NonStop servers advisory that was originally published on March 16th, 2023.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-7ce - subscription required.

Saturday, March 4, 2023

Review - Public ICS Disclosure – Week of 3-3-23

This week we have 25 vendor disclosures from ABB (2), Aruba Networks, BaiCells, Bosch, B&R (2), Hitachi Energy, HPE (7), JTEKT Electronics, Milestone, Reillo, StrongSwan, Tanzu (2), VMware, WAGO, Western Digital, and Wireshark. We also have three vendor updates from HPE (2) and Mitsubishi. Finally we have ten researcher reports for products from Osprey (9) and DJI drones.

Vendor Advisories

ABB Advisory #1 - ABB published an advisory that discusses an improper resource shutdown or release vulnerability in ABB AC 800PEC and AC 800PEC-based products.

ABB Advisory #2 - ABB published an advisory that describes an improper authentication vulnerability in their S+ Operations products.

Aruba Advisory - Aruba published an advisory that describes 33 vulnerabilities in their ArubaOS product.

BaiCells Advisory - BaiCells published an advisory that describes a command injection vulnerability in their EG7035-M11 CPE Series products.

Bosch Advisory - Bosch published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their FL MGUARD and TC MGUARD routers.

B&R Advisory #1 - B&R published an advisory that describes five vulnerabilities in their APROL database.

B&R Advisory #2 - B&R published an advisory that discusses five vulnerabilities in their Mobile Panel and Power Panel products.

Hitachi Energy Advisory - Hitachi published an advisory that describes an update signature validation vulnerability in their Relion® 670, 650 and SAM600-IO Series Products.

HPE Advisory #1 - HPE published an advisory that discusses four improper access control vulnerabilities in their Moonshot/Edgeline Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that discusses a privilege escalation vulnerability in their Apollo, XL Servers.

HPE Advisory #4 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #5 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #6 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #7 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #8 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML/Microserver Servers.

JTEKT Advisory - JP Cert published an advisory that describes three vulnerabilities in the JTEKT Kostac PLC Programming Software.

Milestone Advisory - Milestone published an advisory that announces that their online services no longer support TLS v1.0 and TLS v1.1 protocols.

Riello Advisory - Incibe CERT published an advisory that describes three vulnerabilities in the Riello UPS NetMan 204.

StrongSwan Advisory - StrongSwan published an advisory that describes a certificate verification vulnerability in StrongSwan.

Tanzu Advisory #1 - Tanzu published an advisory that discusses three vulnerabilities in multiple Tanzu products.

Tanzu Advisory #2 - Tanzu published an advisory that discusses two vulnerabilities in multiple Tanzu products.

VMware Advisory - VMware published an advisory that describes a passcode bypass vulnerability in their Workspace ONE Content product.

WAGO Advisory - CERT VDE published an advisory that describes four vulnerabilities in multiple WAGO products.

Western Digital Advisory - Western Digital published an advisory that the latest version of their SanDisk PrivateAccess no longer supports “insecure TLS 1.0 and TLS 1.1 protocols”.

Wireshark Advisory - Wireshark published an advisory that describes a packet injection vulnerability in their ISO 15765 and ISO 10681 dissectors.

Vendor Updates

HPE Update #1 - HPE published an update for their Intel 500 Series Ethernet Controllers advisory that was originally published on February 14th, 2023.

HPE Update #2 - HPE published an update for their ProLiant DL/ML/Microserver Servers that was originally published on February 14th, 2023.

Mitsubishi Update - Mitsubishi published an update for their WEB Server Function on MELSEC Series that was originally published on January 17th, 2023 and most recently updated on January 26th, 2023.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-23-017-02) for this new information.

Researcher Reports

Osprey Report #1 - Zero Science published a report that describes a security bypass vulnerability in the Osprey Pump Controller.

Osprey Report #2 - Zero Science published a report that describes an information disclosure vulnerability in the Osprey Pump Controller.

Osprey Report #3 - Zero Science published a report that describes an administrator backdoor vulnerability in the Osprey Pump Controller.

Osprey Report #4 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #5 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #6 - Zero Science published a report that describes a reflected cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #7 - Zero Science published a report that describes an authentication bypass vulnerability in the Osprey Pump Controller.

Osprey Report #8 - Zero Science published a report that describes a cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #9 - Zero Science published a report that describes a remote code execution vulnerability in the Osprey Pump Controller.

DJI Drones Report - Nico Schiller, et. al. from the Ruhr University Bochum published a report that describes multiple security vulnerabilities in the control system for DJI consumer drones.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-3-3 - subscription require.

 
/* Use this with templates/template-twocol.html */