Showing posts with label Ruijie. Show all posts
Showing posts with label Ruijie. Show all posts

Sunday, December 15, 2024

Review – Public ICS Disclosures – Week of 12-7-24 – Part 2

For Part 2 this week we have 21vvendor updates from Cisco, CODESYS, Palo Alto Networks, and Siemens (18). There are 12 researcher reports about vulnerabilities in products from ABB (9), GeoVision, Phoenix Contact, and Ruijie. Finally, we have an exploit for products from Linear.

Updates

Cisco Update - Cisco published an update for their NX-OS Software Image Verification Bypass advisory that was originally published on December 4th, 2024.

CODESYS Update - CODESYS published an update for their Control Win advisory that was originally published on May 22nd, 2024, and most recently updated on June 5th, 2024.

Palo Alto Networks Update - Palo Alto Networks published an update for their GlobalProtect App advisory that was originally published on November 25th, 2024, and most recently updated on December 6th, 2024.

Siemens Update #1 - Siemens published an update for their Intel-CPUs advisory that was originally published on September 12th, 2023, and  most recently updated on August 13th, 2024.

Siemens Update #2 - Siemens published an update for their Industrial Products advisory that was originally published on May 14th, 2024, and most recently updated on November 12th, 2024.

Siemens Update #3 - Siemens published an update for their SIMATIC S7-1500 advisory that was originally published on October 8th, 2024, and most recently updated on November 12th, 2024.

Siemens Update #4 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on April 9th, 2024, and most recently updated on August 13th, 2024.

Siemens Update #5 - Siemens published an update for their Socket.IO advisory that was originally published on September 10th, 2024, and most recently updated on November 12th, 2024.

Siemens Update #6 - Siemens published an update for their RADIUS Protocol advisory that was originally published on July 9th, 2024, and most recently updated on November 12th, 2024.

Siemens Update #7 - Siemens published an update for their OPC UA Implementation advisory that was originally published on September 12th, 2023, and most recently updated on October 8th, 2024.

Siemens Update #8 - Siemens published an update for their Fortigate NGFW advisory that was originally published on July 9th, 2024, and most recently updated on October 8th, 2024.

Siemens Update #9 - Siemens published an update for their SICAM and SITIPE Products advisory that was originally published on September 10th, 2024.

Siemens Update #10 - Siemens published an update for their Profinet Devices advisory that was originally published on July 13th, 2021, and most recently updated on November 12th, 2024.

Siemens Update #11 - Siemens published an update for their Tecnomatix Plant Simulation advisory that was originally published on October 8th, 2024. - Siemens published an update for their Tecnomatix Plant Simulation advisory that was originally published on October 8th, 2024.

Siemens Update #12 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on April 9th, 2024, and most recently updated on October 8th, 2024.

Siemens Update #13 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2023, and most recently updated on November 12th, 2024.

Siemens Update #14 - Siemens published an update for their Palo Alto Networks Virtual NGFW advisory that was originally published on July 9th, 2024, and most recently updated on November 12th, 2024.

Siemens Update #15 - Siemens published an update for their n SENTRON Powercenter advisory that was originally published on October 8th, 2024.

Siemens Update #16 - Siemens published an update for their OpenSSL X.400 advisory that was originally published on August 8th, 2024, and most recently updated on November 12th, 2024.

Siemens Update #17 - Siemens published an update for their Timing Based Side Channel advisory that was originally published on August 8th, 2023, and most recently updated on December 12th, 2023.

Siemens Update #18 - Siemens published an update for their Protection Mechanism Failure advisory that was originally published on June 13th, 2023, and most recently updated on December 12th, 2023.

Researcher Reports

ABB Reports - Zero Science published nine reports describing vulnerabilities in the ABB Cylon Aspect building energy management product.

GeoVision Report - The Zero Day Initiative published a report that describes a missing authorization vulnerability in the GeoVision GV-ASManager product.

Phoenix Contact Report - Nozomi Networks published a report that describes 12 vulnerabilities in the Phoenix Contact mGuard industrial router.

Ruijie Report - Claroty published a report that describes 10 vulnerabilities in the Ruijie Cloud-Connected Devices.

Exploits

Linear Exploit - Ik-mayne published an exploit for an OS command injection vulnerability in the Linear eMerge e3-Series product.

 

For more information on these updates, reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-3d4 - subscription required. 

Tuesday, December 10, 2024

Review – 6 Advisories and 1 Update Published – 12-10-24

Today CISA’s NCCIC-ICS published six control-system security advisories for products from Rockwell Automation, Horner Automation, National Instruments, Schneider Electric (2), and MOBATIME. They also updated an advisory for products from Ruijie.

Advisories

Rockwell Advisory - This advisory describes four vulnerabilities in the Rockwell Arena product.

Horner Advisory - This advisory describes two out-of-bounds read vulnerabilities in the Horner Cscape product.

National Instruments Advisory - This advisory describes three out-of-bounds read vulnerabilities in the National Instruments Lab View product.

Schneider Advisory #1 - This advisory describes a path traversal vulnerability in the Schneider FoxRTU Station.

Schneider Advisory #2 - This advisory describes three vulnerabilities in the Schneider EcoStruxure Foxboro DCS Core Control Services.

MOBATIME Advisory - This advisory describes a use of default credentials vulnerability in the MOBATIME Network Master Clock - DTS 4801.

Updates

Ruijie Update - This update provides additional information on the Reyee OS advisory that was originally published on December 3rd, 2024.

 

For more information on these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-1-update-published-88e - subscription required. 

Tuesday, December 3, 2024

Review – 6 Advisories and 2 Updates Published – 12-3-24

Today CISA’s NCCIC-ICS published six control system security advisories for products from Fuji Electric (2), ICONICS (and Mitsubishi), Open Automation, Siemens, and Ruijie. They also updated advisories for products from ICONICS (and Mitsubishi) and ETIC.

Advisories

Fuji Advisory #1 - This advisory describes five vulnerabilities in the Fuji Electric Tellus Lite V-Simulator.

Fuji Advisory #2 - This advisory describes 10 out-of-bounds write vulnerabilities in the Fuji Electric Monitouch V-SFT screen configuration software.

ICONICS Advisory - This advisory describes three vulnerabilities in the ICONICS GENESIS64 and Mitsubishi MC Works64 products.

Open Automation Advisory - This advisory describes an incorrect execution-assigned privileges vulnerability in the Open Automation Software package.

Siemens Advisory - This advisory discusses four vulnerabilities (two listed in CISA’s Known Exploited Vulnerabilities catalog) in the Siemens RUGGEDCOM APE1808 products.

Ruijie Advisory - This advisory describes ten vulnerabilities in the Ruijie Reyee OS.

Updates

ICONICS Update - This update provides additional information on the ICONICS and Mitsubishi advisory that was originally published on July 2nd, 2024.

ETIC Update - This update provides additional information on the Remote Access Server advisory that was originally published on November 3, 2022, and most recently updated on July 27th, 2023.

 

For more information on these advisories, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/6-advisories-and-2-updates-published-ee4 - subscription required.

 
/* Use this with templates/template-twocol.html */