Showing posts with label SICK. Show all posts
Showing posts with label SICK. Show all posts

Saturday, March 7, 2026

Review – Public ICS Disclosures – Week of 2-28-26 – Part 1

This week we have bulk vendor disclosures from Broadcom (23). There are 12 additional vendor disclosures from Belden, Dell, Endress+Hauser, HP (2), HPE, Mettler Toledo, Philips, Sick, and WatchGuard (3). We also have 4 vendor updates from Broadcom (4).

Advisories

Belden Advisory - Belden published an advisory that discusses the BlastRadius.Fail vulnerability.

Dell Advisory - Dell published an advisory that discusses 86 vulnerabilities in their ThinOS product.

Endress+Hauser Advisory - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in the Endress+Hauser CC 100 and PFC 200 products.

HP Advisory #1 - HP published an advisory that describes an incorrect default permissions vulnerability in their Event Utility product.

HP Advisory #2 - HP published an advisory that describes a use of hard-coded cryptographic key vulnerability in their SIP Service Providers products.

HPE Advisory - HPE published an advisory that describes six vulnerabilities in their Aruba Networking Wireless Operating Systems.

Mettler Toledo Advisory - CERT-VDE published an advisory that discusses an HTTP request/response smuggling vulnerability (with publicly available exploit) in the Mettler Toledo LabX product.

Philips Advisory - Philips published an advisory that discusses two Cisco Secure Firewall Management Center vulnerabilities.

Sick Advisory - Sick published an advisory that describes two files or directories accessible to external parties vulnerabilities in their Lector85x and Lector83x products.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes an expected behavior violation vulnerability in their FirewareOS products.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes a cross-site scripting vulnerability in their Fireware OS Web UI products.

WatchGuard Advisory #3 - WatchGuard published an advisory that describes an out-of-bounds write vulnerability in their Fireware OS products.

Updates

Broadcom Update #1 - Broadcom published an update for their Fabric OS Web application advisory that was originally published on May 10th, 2021.

Broadcom Update #2 - Broadcom published an update for their Fabric OS advisory that was originally published on September 27th, 2024, and most recently updated on January 28th, 2026.

Broadcom Update #3 - Broadcom published an update for their Brocade SANnav advisory that was originally published on October 15th, 2024, and most recently updated on February 19th, 2026.

Broadcom Update #4 - Broadcom published an update for their Brocade ASCG advisory that was originally published on January 8th, 2025, and most recently updated on February 19th, 2026.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-04b - subscription required.

Saturday, February 28, 2026

Review – Public ICS Disclosures – Week of 2-21-26 - Part 1

We have a busy disclosure week. For Part 1 we have 17 vendor disclosures from ABB (2), Dell, Festo, Fujitsu, Hitachi (2), Hitachi Energy (3), HP (2), HPE (3), Sick, and Supermicro.

Advisories

ABB Advisory #1 - ABB published an advisory that discusses an insecure default initialization of resource vulnerability in their Automation Builder product.

ABB Advisory #2 - ABB published an advisory that discusses three vulnerabilities in their AC500 V3 products.

Dell Advisory - Dell published an advisory that describes four vulnerabilities in their Wyse Management Suite.

Festo Advisory - CERT-VDE published an advisory that 126 vulnerabilities in the Festo Automation Suite product. These are third-party (CODESYS) vulnerabilities.

Fujitsu Advisory - JP-CERT published an advisory that describes an out-of-bounds write vulnerability in the Fujitsu Fujitsu BIOS Driver.

Hitachi Advisory #1 - Hitachi published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Configuration Manager and Ops Center API Configuration Manager products.

Hitachi Advisory #2 - Hitachi published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Configuration Manager and Ops Center API Configuration Manager products.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes four vulnerabilities (one with publicly available exploit) in their RTU500 series CMU Firmware.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that describes two vulnerabilities in their Relion REB500 Product.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that discusses a deserialization of untrusted data vulnerability in their Ellipse product.

HP Advisory #1 - HP published an advisory that discusses four vulnerabilities (two with publicly available exploits) in their LaserJet Enterprise and LaserJet Managed Printers.

HP Advisory #2 - HP published an advisory that describes three improper check for unusual or exceptional conditions vulnerabilities in multiple product lines utilizing the Intel NPU driver.

HPE Advisory #1 - HPE published an advisory that describes an authentication bypass vulnerability in their AutoPass License Server (APLS).

HPE Advisory #2 - HPE published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in their ProLiant AMD DL/XL Servers.

HPE Advisory #3 - HPE published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in their SimpliVity Servers.

Sick Advisory - Sick published an advisory that describes two use of risky or broken cryptographic algorithm vulnerabilities in their LMS1000 and MRS1000 products.

Supermicro Advisory - Supermicro published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability in multiple products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-805 - subscription required.

Saturday, February 21, 2026

Review – Public ICS Disclosures – Week of 2-14-26 – Part 1

This was a moderately busy disclosure week. For Part 1 we have bulk vendor disclosures from HPE (6). We have 12 additional vendor disclosures from Arista, Broadcom (2), B&R Automation, Dassault Systems (4), Hitachi, HP, Philips, and Sick.

Bulk Vendor Disclosures – HPE

HPESBHF04864 rev.1 - Certain HPE SimpiVity Servers Using Certain Intel Processors, INTEL-SA-01244, 2025.2 IPU, Intel Processor Advisory, Local Denial of Service Vulnerability,

HPESBNW04983 rev.1 - HPE Telco Service Orchestrator software, Prototype Pollution Vulnerability,

HPESBHF04967 rev.1 - Certain HPE SimpliVity Servers Using Certain Intel Processor BIOS, INTEL-SA-01234, 2025.3 IPU, UEFI Reference Firmware Advisory., Multiple Vulnerabilities,

HPESBNW05011 rev.1 - Telco Service Activator, Improper Input Validation,

HPESBNW05012 rev.1 - Local Privilege Escalation Vulnerability in HPE Aruba Networking ClearPass Policy Manager (CPPM) OnGuard Software for Linux,

HPESBNW04998 rev.1 - Prototype Pollution Vulnerability in HPE Telco Network Function Virtualization Orchestrator

Advisories

Arista Advisory - Arista published an advisory that describes an operation on a resource after expiration or release vulnerability on multiple platforms running their EOS software.

Broadcom Advisory #1 - Broadcom published an advisory that discusses an improper neutralization of a NULL byte or NUL character vulnerability in their Brocade SANnav base OS.

Broadcom Advisory #2 - Broadcom published an advisory that discusses an out-of-bounds write vulnerability in their Brocade SANnav OVA products.

B&R Advisory - B&R published an advisory that discusses 25 vulnerabilities in their Automation Studio product.

Dassault Advisory #1 - Dassault published an advisory that describes a cross-site scripting vulnerability in their ENOVIAvpm Web Access product.

Dassault Advisory #2 - Dassault published an advisory that describes an out-of-bounds write vulnerability in their EPRT file reading procedure in SOLIDWORKS eDrawings.

Dassault Advisory #3 - Dassault published an advisory that describes an out-of-bounds read vulnerability in their EPRT file reading procedure in SOLIDWORKS eDrawings.

Dassault Advisory #4 - Dassault published an advisory that describes a use of uninitialized variable in their EPRT file reading procedure in SOLIDWORKS eDrawings.

Hitachi Advisory - Hitachi published an advisory that discusses 72 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities.

HP Advisory - HP published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their Samsung MultiXpress Multifunction Printers.

Philips Advisory - Philips published an advisory that discusses a Google Chrome use after free vulnerability.

Sick Advisory - Sick published an advisory that discusses two Eclipse Cyclone DDS vulnerabilities.

 

For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-fb5 - subscription required.

Sunday, February 8, 2026

Review – Public ICS Disclosures – Week of 1-31-26 – Part 2

For Part 2 we have four additional vendor disclosures from Sick (3) and Zyxel. There are seven vendor updates from Broadcom (3), ELECOM (2), HPE, and Moxa. Finally, we have an exploit for products from MySCADA.

Advisories

Sick Advisory #1 - Sick published an advisory that describes 15 vulnerabilities in their TDC-X401GL telematic data collector.

Sick Advisory #2 - Sick published an advisory that describes 12 vulnerabilities
(one with publicly available exploit) in their Incoming Goods Suite.

Sick Advisory #3 - Sick published an advisory that discusses an out-of-bounds read vulnerability in their nanoScan3 and microScan3 products.

Zyxel Advisory - Zyxel published an advisory that describes an OS command injection vulnerability in their ZLD firewalls.

Updates

Broadcom Update #1 - Broadcom published an update for their Brocade Fabric advisory that was originally published on January 27th, 2026.

Broadcom Update #2 - Broadcom published an update for their Brocade Fabric OS advisory that was originally published on January 27th, 2026.

Broadcom Update #3 - Broadcom published an update for their Brocade Fabric OS advisory that was originally published on January 27th, 2026.

ELECOM Update #1 - JPCERT published an update for their ELECOM wireless LAN routers advisory that was originally published on August 27th, 2024, and most recently updated on February 12th, 2025.

ELECOM Update #2 - JPCERT published an update for their ELECOM wireless LAN routers advisory that was originally published on March 26th, 2024, and most recently updated on November 26th, 2024.

HPE Update - HPE published an update for their HPE ProLiant DL/ML/XD, Alletra, and Synergy Servers advisory that was originally published on December 12th, 2025, and most recently updated on January 5th, 2026.

Moxa Update - Moxa published an update for their Diffie-Hellman Key Exchange Protocol advisory that was originally published on June 2nd, 2025, and most recently updated on January 5th, 2026.

Exploits

MySCADA Exploit - Indoushka published an exploit for an OS command injection vulnerability in the MySCADA MyPRO Manager product.

Saturday, November 1, 2025

Review – Public ICS Disclosures – Week of 10-25-25

This week we have bulk vendor disclosures from HP (6). We have 11 additional vendor disclosures from Circutor, Hitachi Energy, HPE, Moxa, Philips, QNAP, Ruckus, Sick (2), Supermicro, and WatchGuard. There are bulk updates from HP (6). We have six additional vendor updates from ABB, Hitachi Energy, and Moxa (4). Finally, we have a researcher report of a vulnerability in products from MPDV Mikrolab.

Bulk Disclosures – HP

HP Client Management Script Library – Security Update,

AMD Graphics August 2025 Security Update,

HP Card Readers (B Models) – Potential Information Disclosure,

NVIDIA GPU Display Driver October 2025 Security Update,

Intel Xeon Processor Firmware August 2025 Security Update,

HP ThinPro 8.1 SP8 Security Updates.

Advisories

Circutor Advisory - INCIBE-CERT published an advisory that describes 12 vulnerabilities in the Circutor SGE-PLC100 and SGE-PLC50 concentrators.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses the BlastRadius-Fail vulnerability.

HPE Advisory - HPE published an advisory that describes seven vulnerabilities in their Private Cloud AI product.

Moxa Advisory - Moxa published an advisory that discusses an inadequate encryption strength vulnerability in multiple Moxa product lines.

Philips Advisory - Philips published an advisory that discusses a Windows remote code execution vulnerability that is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

QNAP Advisory - QNAP published an advisory that discusses an HTTP request/response smuggling vulnerability (with publicly available exploit) in their NetBak PC Agent.

Ruckus Advisory - Ruckus published an advisory that describes “a number of vulnerabilities in access control and privilege escalation” in their RUCKUS Network Director.

Sick Advisory #1 - Sick published an advisory that discusses an inclusion of functionality from untrusted control sphere vulnerability (listed in CISA’s KEV and has publicly available exploit) in their SID products.

Sick Advisory #2 - Sick published an advisory that describes six vulnerabilities in their TLOC100-100 product.

Supermicro Advisory - Supermicro published an advisory that discusses an improper handling of insufficient entropy vulnerability in multiple Supermicro products.

WatchGuard Advisory - WatchGuard published an advisory that describes a command injection vulnerability in their Mobile VPN product.

Bulk Updates – HP

Intel Rapid Storage Technology Software August 2025 Security Update,

HP Hotkey Support – Escalation of Privilege,

NVIDIA GPU Display Driver January 2025 Security Update,

NVIDIA GPU Display Driver July 2025 Security Update,

Intel System Security Report and System Resources Defense, and

Intel Graphics Software August 2025 Security Update

Updates

ABB Update - ABB published an update for their Terra AC wallbox advisory that was originally published on September 16th, 2025, and most recently updated on October 9th, 2025.

Hitachi Energy Update - Hitachi Energy published an update for their Asset Suite advisory that was originally published on September 30th, 2025.

Moxa Update #1 - Moxa published an update for their Ethernet Switch advisory that was originally published on October 23rd, 2025.

Moxa Update #2 - Moxa published an update for their Secure Routers advisory that was originally published on April 2nd, 2025, and most recently updated on May 5th, 2025.

Moxa Update #3 - Moxa published an update for their Secure Routers advisory that was originally published on April 2nd, 2025.

Moxa Update #4 - Moxa published an update for their ICMP Timestamp advisory that was originally published on October 21st, 2025.

Researcher Reports

MPDV Mikrolab Report - SEC Consult published a report that describes a path traversal vulnerability in the MPDV MIP 2, FEDRA 2, and HYDRA X Manufacturing Execution Systems.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-0e8 - subscription required.

Sunday, October 19, 2025

Review – Public ICS Disclosures – Week of 10-11-25 – Part 2

For Part 2 we have 11 additional vendor disclosures from Phoenix Contact (2), Rockwell Automation (2), Schneider, Sick (2), Supermicro, and Westermo (3). We have 20 bulk updates from Schneider (5), and Siemens (15). We have three additional vendor updates from B&R Automation, CODESYS, and HP. Finally, we have four researcher reports describing vulnerabilities in products from Red Lion and Ilevia (3).

Advisories

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory that describes four vulnerabilities in their QUINT4-UPS EIP uninterruptible power supplies.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory that describes a code injection vulnerability in their CHARX SEC-3xxx charging controllers.

Rockwell Advisory #1 - Rockwell published an advisory that describes an uncaught exception vulnerability in their Compact GuardLogix 5370 product. Rockwell

Rockwell Advisory #2 - Rockwell published an advisory that describes two vulnerabilities in their 1715 EtherNet/IP Comms Module.

Schneider Advisory - Schneider published an advisory that describes an allocation of resources without limits or throttling vulnerability in their EcoStruxure OPC UA Server Expert and EcoStruxure Modicon Communication Server products.

Sick Advisory #1 - Sick published an advisory that describes 18 vulnerabilities in their Enterprise Analytics and Logistic Analytics products.

Sick Advisory #2 - Sick published an advisory that discusses 28 vulnerabilities in their Endress+Hauser SSG-E210GC. These are third-party vulnerabilities.

Supermicro Advisory - Supermicro published an advisory that discusses an improper access control vulnerability.

Westermo Advisory #1 - Westermo published an advisory that describes a cleartext transmission of sensitive information vulnerability in their RADIUS Server Groups.

Westermo Advisory #2 - Westermo published an advisory that describes a cleartext transmission of sensitive information in their WeOS 5.

Westermo Advisory #3 - Westermo published an advisory that describes an improper restriction of communications channel to expected endpoints vulnerability in their WeOS 5.

Bulk Updates

Schneider

Multiple Altivar Process Drives and Communication Modules,

Modicon Controllers M241 / M251, M258 / LMC058 and M262,

Modicon M241 / M251 / M258 / LMC058,

FlexNet Publisher Vulnerability, and

Modicon Controllers M241 / M251 / M258 / LMC058

Siemens

Vulnerability in Nozomi Guardian/CMC on RUGGEDCOM APE1808 Devices,

Open Redirect Vulnerability in SIMATIC S7-1500 and S7-1200 CPUs,

Multiple Vulnerabilities in User Management Component (UMC),

Deserialization Vulnerability in Siemens Engineering Platforms,

Denial of Service Vulnerabilities in User Management Component (UMC),

Multiple Vulnerabilities in Palo Alto Networks Virtual NGFW on RUGGEDCOM APE1808 Devices,

Deserialization Vulnerability in Siemens Engineering Platforms,

Buffer Overflow Vulnerability in RUGGEDCOM ROS Devices,

Improper Integrity Check of Firmware Updates in SiPass integrated AC5102 / ACC-G2 and ACC-AP,

DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery,

Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1,

XML External Entity (XXE) Injection Vulnerability in SIMOTION SCOUT,

Multiple Vulnerabilities in RUGGEDCOM ROS Devices,

Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs, and

Heap-based Buffer Overflow Vulnerability in User Management Component (UMC).

Updates

B&R Update - B&R published an update for their System Diagnostic Manager advisory that was originally published on October 7th, 2025.

CODESYS Update - CODESYS published an update for their Control V3 advisory that was originally published on August 4th, 2025, and most recently updated on September 1st, 2025.

HP Update - HP published an update for their Intel 2024.3 IPU advisory that was originally published on October 24th, 2024, and most recently updated on March 31st, 2025.

Researcher Reports

Red Lion Report - Claroty published a report describing two vulnerabilities in the Red Lion Sixnet RTU’s.

Ilevia Reports - Zero Science published four reports describing vulnerabilities in the Ilevia EVE X1 Server. The reports include links to exploits.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-568 - subscription required.

Saturday, May 3, 2025

Review – Public ICS Disclosures – Week of 4-26-25 – Part 1

For Part 1 this week we have 11 vendor disclosures from ABB (3), Bosch, Broadcom, Dassault Systems (2), HPE, Philips, and Sick (2).

Advisories

ABB Advisory #1 - ABB published an advisory that describes three vulnerabilities in their ABB Network Card.

ABB Advisory #2 - ABB published an advisory that describes two vulnerabilities in their Automation Builder product.

ABB Advisory #3 - ABB published an advisory that discusses an access of uninitialized pointer vulnerability in their Ekip Com IEC61850 product.

Bosch Advisory - Bosch published an advisory that describes 15 vulnerabilities (with publicly available exploits) in their Rexroth AG ctrlX OS products.

Broadcom Advisory - Broadcom published an advisory that discusses two vulnerabilities in multiple Brocade products.

Dassault Systems Advisory #1 - Dassault Systems published an advisory that describes a use-after-free vulnerability in their SOLIDWORKS eDrawings.

Dassault Systems Advisory #2 - Dassault Systems published an advisory that describes an out-of-bounds write vulnerability in their SOLIDWORKS eDrawings application.

HPE Advisory - HPE published an advisory that discusses a heap-based buffer overflow vulnerability in their Superdome Flex, Superdome Flex 280, and Compute Scale-up Server 3200 products.

Philips Advisory - Philips published an advisory that discusses the SAP NetWeaver vulnerability.

Sick Advisory #1 - Sick published an advisory that describes two vulnerabilities in their Flexi Compact products.

Sick Advisory #2 - Sick published an advisory that describes 23 vulnerabilities in their picoScan and multiScan products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-a52 - subscription required.

Sunday, March 16, 2025

Review – Public ICS Disclosures – Week of 3-8-25 – Part 2

For Part 2 we have three additional vendor disclosures from SEL, Sick, and Zyxel. There are also 21 vendor updates for products from Broadcom, HP, HPE, Schneider (2), and Siemens (16). Finally, we have six exploits for vulnerabilities in products from ABB (2), Foundstone, GE, WinTr, and Yokogawa.

Advisories

SEL Advisory - SEL published an update notice for their SEL-5032 acSELerator Architect Software that included a cybersecurity enhancement.

Sick Advisory - Sick published an advisory that describes three vulnerabilities in their SICK DL100-2xxxxxxx.

Zyxel Advisory - Zyxel published an advisory that describes three OS command injection vulnerabilities in multiple Zyxel product lines.

Updates

Broadcom Update - Broadcom published an update for their Brocade ASCG Vulnerability advisory that was originally published on January 7th, 2025, and most recently updated on February 27th, 2025.

HP Update - HP published an update for their HP LaserJet Pro advisory that was originally published on February 14th, 2025.

HPE Update - HPE published an update for their Aruba Networking Access Points advisory that was originally published on August 3rd, 2024, and most recently updated on August 15th, 2024.

Schneider Update #1 - Schneider published an update for their Modicon M241 advisory that was originally published on December 10th, 2024.

Schneider Update #2 - Schneider published an update for their EcoStruxure Power Monitoring Expert advisory that was originally published on October 8th, 2024.

Siemens Update #1 - Siemens published an update for their User Management Component advisory that was originally published on December 16th, 2024.

Siemens Update #2 - Siemens published an update for their n SIMATIC S7-1500 advisory that was originally published on October 8th, 2024, and most recently updated on January 14th, 2025.

Siemens Update #3 - Siemens published an update for their Fortigate NGFW advisory that was originally published on March 12th, 2024, and most recently updated on February 11th, 2025.

Siemens Update #4 - Siemens published an update for their Fortigate NGFW advisory that was originally published on February 11th, 2025.

Siemens Update #5 - Siemens published an update for their SIPROTEC 5 advisory that was originally published on February 11th, 2025.

Siemens Update #6 - Siemens published an update for their Radius Protocol advisory that was originally published on July 9th, 2024, and most recently updated on January 14th, 2025.

Siemens Update #7 - Siemens published an update for their Radius Protocol advisory that was originally published on July 9th, 2024, and most recently updated on January 14th, 2025.

Siemens Update #8 - Siemens published an update for their SegmentSmack advisory that was originally published on April 14th, 2020, and most recently updated on January 14th, 2025.

Siemens Update #9 - Siemens published an update for their DHCP Client advisory that was originally published on November 12th, 2019, and most recently updated on February 13th, 2024.

Siemens Update #10 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2022, and most recently updated February 11th, 2025.

Siemens Update #11 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on April 9th, 2024, and most recently updated on February 11th, 2025.

Siemens Update #12 - Siemens published an update for their Nucleus RTOS advisory that was originally published on April 13th, 2021, and most recently updated on February 13th, 2023.

Siemens Update #13 - Siemens published an update for their SIMATIC Products Webserver advisory that was originally published on February 11th, 2025.

Siemens Update #14 - Siemens published an update for their SIPROTEC 5 Webserver advisory that was originally published on January 14th, 2025, and most recently updated on February 11th, 2025.

Siemens Update #15 - Siemens published an update for their SIMATIC S7-1500 CPUs Webserver advisory that was originally published on October 8th, 2024, and most recently updated on January 14th, 2025.

Siemens Update #16 - Siemens published an update for their User Management Component advisory that was originally published on September 10th, 2024, and most updated on January 14th, 2025.

Exploits

ABB Exploit #1 - Indoushka published an exploit for two vulnerabilities in the ABB AC500.

ABB Exploit #2 - Indoushka published an exploit for a shell upload vulnerability in the ABB Cylon Aspect.

Foundstone Exploit - Ahmet Ümit Bayram published an exploit for a buffer overflow vulnerability in the Foundstone SuperScan product.

GE Proficy Exploit - Indoushka published an exploit for a directory traversal vulnerability in the GE Proficy Cimplicity 7 product.

VMware Exploit - Indoushka published an exploit for an ASP.NET misconfiguration: use of identity impersonation vulnerability in the VMware vCenter Server product.

WinTR Exploit - Ahmet Ümit Bayram published an exploit for a command injection vulnerability in the WinTR Scada product.

Yokogawa Exploit - Indoushka published an exploit for an improper restriction of operation within the bounds of a memory buffer vulnerability in the Yokogawa CENTUM CS 3000.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-fdf - subscription required.

Saturday, March 8, 2025

Review – Public ICS Disclosures – Week of 3-1-25 – Part 1

This week for Part 1 we have 17 vendor disclosures from Broadcom, HP, Meinberg, Moxa, QNAP (10), Rockwell Automation, Sick, and Supermicro.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses a use after free vulnerability (with publicly available exploit) in their Brocade SANnav, Brocade Support Link, and Brocade Switches.

HP Advisory - HP published an advisory that discusses 233 vulnerabilities in their ThinPro products.

Meinberg Advisory - Meinberg published an advisory that discusses 13 vulnerabilities (4 with publicly available exploits) in their LANTIME product.

Moxa Advisory - Moxa published an advisory that describes a reliance on security through obscurity vulnerability in their PT Switches.

QNAP Advisory #1 - QNAP published an advisory that describes a TOCTOU race condition vulnerability in multiple QNAP products.

QNAP Advisory #2 - QNAP published an advisory that describes a server-side request forgery vulnerability in multiple QNAP products.

QNAP Advisory #3 - QNAP published an advisory that describes an out-of-bounds write vulnerability in their QTS and QuTS hero products.

QNAP Advisory #4 - QNAP published an advisory that describes six vulnerabilities in QTS and QuTS hero products.

QNAP Advisory #5 - QNAP published an advisory that describes a files or directories accessible to external parties vulnerability in their File Station 5 product.

QNAP Advisory #6 - QNAP published an advisory that describes an OS command injection vulnerability in their QuRouter product.

QNAP Advisory #7 - QNAP published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in Legacy QTS and QuTS hero products.

QNAP Advisory #8 - QNAP published an advisory that describes an improper certificate validation vulnerability in their Helpdesk product.

QNAP Advisory #9 - QNAP published an advisory that describes a classic buffer overflow vulnerability in their HBS 3 Hybrid Backup Sync product.

QNAP Advisory #10 - QNAP published an advisory that describes an OS command injection vulnerability in their QuRouter product.

Rockwell Advisory - Rockwell published an advisory that discusses three vulnerabilities (all listed in CISA’s Known Exploited Vulnerabilities catalog) in multiple Rockwell products used with VMware.

Sick Advisory - Sick published an advisor that discusses 16 vulnerabilities in multiple Sick products.

Supermicro Advisory - Supermicro published an advisory that discusses an improper signature verification vulnerability in multiple Supermicro products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-40b - subscription required.

Sunday, March 2, 2025

Review – Public ICS Disclosures – Week of 2-21-25 – Part 2

For Part 2 we have five additional vendor disclosures from Planex Communications, SEL (2), Sick, and Sierra Wireless. There are also eight vendor updates from Broadcom (4), Dell, Hitachi Energy, HPE, and Sick. There is a researcher report for vulnerabilities in products from Siemens. Finally, we have an exploit for products from FortiGuard.

Advisories

Planex Advisory - JP-CERT published an advisory that describes two vulnerabilities in the Planex Wireless LAN routers.

SEL Advisory #1 - SEL published a software update notice that included cybersecurity enhancements to fix six third-party vulnerabilities (one with publicly available exploit) for their SEL-3350 product.

SEL Advisory #2 - SEL published a software update notice that included cybersecurity enhancements to fix three third-party vulnerabilities for their SEL-3355-2 and SEL-3360-2 products.

Sick Advisory - Sick published an advisory that describes two vulnerabilities in their Lector8xx and InspectorP8xx products.

Sierra Wireless Advisory - Semtech published an advisory that discusses the 5Ghoul vulnerabilities in their s EM919x and EM929x cellular modules.

Updates

Broadcom Update #1 - Broadcom published an update for their Brocade Fabric OS advisory that was originally published on September 26th, 2024, and most recently updated on January 7th, 2025.

Broadcom Update #2 - Broadcom published an update for their Brocade SANnav advisory that was originally published on October 14th, 2024, and most recently updated on February 13th, 2024.

Broadcom Update #3 - Broadcom published an update for their Brocade ASCG advisory that was originally published on January 7th, 2025, and most recently updated on February 13th, 2025.

Broadcom Update #4 - Broadcom published an update for their compromised container advisory that was originally published on October 14th, 2024.

Dell Update - Dell published an update for their ThinOS advisory that was originally published on September 9th, 2024.

Hitachi Energy Update - Hitachi Energy published an update for their Relion 670/650/SAM600-IO series advisory that was originally published on November 4th, 2021, and most recently updated on March 14th, 2023.

HPE Update - HPE published an update for their ProLiant DL/ML advisory that was originally published on February 11th, 2025.

Sick Update - Sick published an update for their MEAC300 advisory that was originally published on February 14th, 2025.

Researcher Reports

Siemens Report - SEC Consult published a report describing two vulnerabilities in the Siemens A8000 CP-8050 and CP-8031 PLCs.

Exploits

FortiGuard Exploit - Indoushka published an exploit for a code execution vulnerability in the FortiGuard FortiManager product.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-ef6 - subscription required.

Saturday, February 22, 2025

Review – Public ICS Disclosures – Week of 2-15-25

It was a relatively light disclosure week, I needed that after last week. We have 12 vendor disclosures from HPE (2), Moxa (5), Philips (2), Omron, Sick (2), and Wireshark. We have 4 vendor updates from Broadcom (2) and HPE (2).

Advisories

HPE Advisory #1 - HPE published an advisory that discusses four vulnerabilities (one with publicly available exploit) in their Telco Service Orchestrator.

HPE Advisory #2 - HPE published an advisory that discusses three vulnerabilities in their Telco Service Orchestrator.

Moxa Advisory #1 - Moxa published an advisory that describes an improper validation of specified type of input vulnerability in their EDS, ICS, IKS, and SDS Switches.

Moxa Advisory #2 - Moxa published an advisory that describes an out-of-bounds write vulnerability in their EDS, ICS, IKS, and SDS Switches.

Moxa Advisory #3 - Moxa published an advisory that describes a missing authentication for critical function vulnerability in their ethernet switches.

Moxa Advisory #4 - Moxa published an advisory that describes an improper validation of specified type of input vulnerability in their PT Switches.

Moxa Advisory #5 - Moxa published an advisory that describes an out-of-bounds write vulnerability in their PT Switches.

Philips Advisory #1 - Philips published an advisory that discusses four Ivanti Endpoint Manager vulnerabilities.

Philips Advisory #2 - Philips published an advisory that discusses a cross-site scripting vulnerability that is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Omron Advisory - Omron published an advisory that describes an out-of-bounds read vulnerability in their CX-Programmer product.

Sick Advisories - The Sick PSIRT page lists two recent advisories for Sick products. Unfortunately, both the .pdf and JSON files are currently returning a 503, Service Unavailable, error message.

Wireshark Advisory - Wireshark published an advisory that describes an uncontrolled recursion vulnerability in their Bundle Protocol and CBOR dissector crash products.

Updates

Broadcom Update #1 - Broadcom published an update for their OpenSSH advisory that was originally published on December 9th, 2024, and most recently updated on February 13th, 2025.

Broadcom Update #2 - Broadcom published an update for their embedded switch SNMP commands advisory that was originally published on July 30th, 2024.

HPE Update #1 - HPE published an update for their Telco Service Orchestrator advisory that was originally published on January 20th, 2025.

HPE Update #2 - HPE published an update for their Telco Service Orchestrator SO, Apache Log4j advisory that was originally published on December 17th, 2021.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-7a6 - subscription required.

Saturday, December 14, 2024

Review – Public ICS Disclosures – Week of 12-7-24 – Part 1

This week we have 32 vendor disclosures from HP, HPE (12), Palo Alto Networks, Phoenix Contact (2), QNAP (3), Schneider (3), SEL, SICK, Splunk (7), and Supermicro.

Advisories

HP Advisory - HP published an advisory that describes an uncaught exception vulnerability in multiple business computers.

HPE Advisory #1 - HPE published an advisory that describes two vulnerabilities (one with multiple publicly available exploits) in their Aruba Networking AirWave Management Platform.

HPE Advisory #2 - HPE published an advisory that discusses an improper FMS in hardware logic vulnerability in their SimpliVity Servers.

HPE Advisory #3 - HPE published an advisory that discusses an incorrect order behavior vulnerability in the SimpliVity Servers.

HPE Advisory #4 - HPE published an advisory that discusses four vulnerabilities in their SimpliVity Servers.

HPE Advisory #5 - HPE published an advisory that discusses an improper FMS in hardware logic vulnerability in their SimpliVity Servers.

HPE Advisory #6 - HPE published an advisory that discusses two vulnerabilities in their SimpliVity Servers.

HPE Advisory #7 - HPE published an advisory that discusses an insufficient control flow management vulnerability in their SimpliVity Servers.

HPE Advisory #8 - HPE published an advisory that discusses two vulnerabilities in their SimpliVity Servers.

HPE Advisory #9 - HPE published an advisory that discusses a code injection vulnerability in their SimpliVity AMD Servers.

HPE Advisory #10 - HPE published an advisory that discusses a sensitive information in resource not removed before reuse vulnerability in their SimpliVity Servers.

HPE Advisory #11 - HPE published an advisory that discusses an observable discrepancy vulnerability in their SimpliVity Servers.

HPE Advisory #12 - HPE published an advisory that discusses four vulnerabilities in their Telco Service Orchestrator.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses two type confusion vulnerabilities in their Prisma Access Browser.

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory that discusses six vulnerabilities (one with publicly available exploit) in their PLCNext products.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory that discusses 63 vulnerabilities in their PLCNext products.

QNAP Advisory #1 - QNAP published an advisory that describes a link following vulnerability in their Qsync Central product.

QNAP Advisory #2 - QNAP published an advisory that describes eight vulnerabilities in their QTS and QuTS hero products that were reported during a recent PWN-to-OWN competition.

QNAP Advisory #3 - QNAP published an advisory that describes an OS command injection vulnerability in their License Center product.

Schneider Advisory #1 - Schneider published an advisory that describes an improper authentication vulnerability in their PowerChute Serial Shutdown product.

Schneider Advisory #2 - Schneider published an advisory that describes a use of unmaintained third-party components vulnerability in their Harmony HMI and Pro-face HMI products.

Schneider Advisory #3 - Schneider published an advisory that describes an improper input validation vulnerability in their Modicon controllers.

SEL Advisory - SEL published a version update notice for their SEL-5037 SEL Grid Configurator that reported a cybersecurity enhancement.

SICK Advisory - SICK published an advisory that describes six vulnerabilities in their InspectorP61x, InspectorP62x and TiM3xx products.

Splunk Advisory #1 - Splunk published an advisory that discusses an exposure of sensitive information vulnerability in their Universal Forwarder.

Splunk Advisory #2 - Splunk published an advisory that discusses 11 vulnerabilities in their Enterprise product.

Splunk Advisory #3 - Splunk published an advisory that describes a deserialization of untrusted data vulnerability in their Secure Gateway app.

Splunk Advisory #4 - Splunk published an advisory that describes a cleartext transmission of sensitive information vulnerability in their Enterprise product SPL commands.

Splunk Advisory #5 - Splunk published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their Enterprise product.

Splunk Advisory #6 - Splunk published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their Enterprise product.

Splunk Advisory #7 - Splunk published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their Enterprise product.

Supermicro Advisory - Supermicro published an advisory that describes a memory address aliasing vulnerability in their EPYC 3rd and 4th Gen Processors.

 

For more information on these advisories, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-2f8 - subscription required.

Saturday, November 23, 2024

Review – Public ICS Disclosures – Week of 11-16-24

This week we have 21 vendor disclosures from Dassault Systems, HPE, Palo Alto Networks (2), Philips (2), QNAP (8), Sick, WAGO, Westermo (2), Wireshark (2), and Zyxel. There are also seven vendor updates from FortiGuard, Mitsubishi, Moxa (4), and VMware. We also have three researcher reports for vulnerabilities in products from MC Technologies (2) and Mongoose Web Server Library. Finally, we have three exploits for products from Korenix, Palo Alto Networks, and Siemens.

Advisories

Dassault Systems Advisory - Dassault Systems published an advisory that describes two vulnerabilities in their eDrawings product.

HPE Advisory - HPE published an advisory that describes an improper handling of exceptional conditions vulnerability in their NonStop DISK UTIL.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes an OS command injection vulnerability {listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog} in their PAN-OS products.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a missing authentication for critical function vulnerability {listed in CISA’s KEV catalog} in their PAN-OS products.

Philips Advisory #1 - Philips published an advisory that discusses an argument injection vulnerability reported by Laravel.

Philips Advisory #2 - Philips published an advisory that discusses an improper authentication vulnerability {listed in CISA’s KEV catalog} reported by Microsoft in their Windows Scheduler.

QNAP Advisory #1 - QNAP published an advisory that describes four vulnerabilities in their Notes Station 3.

QNAP Advisory #2 - QNAP published an advisory that discusses three vulnerabilities in their QTS and QTS Hero products.

QNAP Advisory #3 - QNAP published an advisory that describes four cross-site scripting vulnerabilities in their Photo Station products.

QNAP Advisory #4 - QNAP published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their AI Core product.

QNAP Advisory #5 - QNAP published an advisory that describes a link following vulnerability in their QuLog Center product.

QNAP Advisory #6 - QNAP published an advisory that describes 15 vulnerabilities in their QTS and QuTS hero products.

QNAP Advisory #7 - QNAP published an advisory that describes two OS command injection vulnerabilities in their QuRouter product.

QNAP Advisory #8 - QNAP published an advisory that describes an authorization bypass through user controlled key vulnerability in their Media Streaming Add-on.

Sick Advisory - Sick published an advisory that describes an execution with unnecessary privileges vulnerability in their  Incoming Goods Suite.

WAGO Advisory - CERT-VDE published an advisory that describes eight vulnerabilities in the firmware of multiple WAGO products.

Westermo Advisory #1 - Westermo published an advisory that discusses an out-of-bounds write vulnerability (with publicly available exploit) in their WeOS.

Westermo Advisory #2 - Westermo published an advisory that discusses the Blast-Radius vulnerabilities in their WeOS products

Wireshark Advisory #1 - Wireshark published an advisory that describes an ECMP dissector crash vulnerability.

Wireshark Advisory #2 - Wireshark published an advisory that describes an FiveCo RAP dissector infinite loop vulnerability.

Zyxel Advisory - Zyxel published an advisory that discusses recent attempts by threat actors to target Zyxel firewalls through previously disclosed vulnerabilities.

Updates

FortiGuard Update #1 - FortiGuard published an update for their CONTINUATION Frames advisory that was originally published on May 14th, 2024.

FortiGuard Update #2 - FortiGuard published an update for their regreSSHion advisory that was originally published on July 9th, 2024, and most recently updated on November 15th, 2024.

Mitsubishi Update - Mitsubishi published an update for their Ethernet port advisory that was originally published on November 30th, 2021, and most recently updated on November 9th, 2023.

Moxa Update #1 - Moxa published an update for their Ethernet Switches advisory that was originally published on November 1st, 2024.

Moxa Update #2 - Moxa published an update for their MDS-G4028-L3 Series advisory that was originally published on November 4th, 2024.

Moxa Update #3 - Moxa published an update for their Cellular Routers advisory that was originally published on October 14th, 2024, and most recently updated on October 25th, 2024.

Moxa Update #4 - Moxa published an update for their SSLv2 Vulnerabilities advisory that was originally published on March 31st, 2016.

VMware Update - VMware published an update for their vCenter Server advisory that was originally published on September 17th, 2024, and most recently updated on October 21st, 2024.

Researcher Reports

MC Technologies Reports - Cisco Talos published two reports covering four OS command injection vulnerabilities in the MC Technologies MC LR Router web interface.

Mongoose Web Server Report - Nozomi Networks published a report describing ten vulnerabilities in the Mongoose Web Server Library.

Exploits

Korenix Exploit - St. Pölten UAS published an exploit for a path traversal vulnerability in the Korenix JetPort 5601.

Palo Alto Networks Exploit - Sachinart published an exploit for a missing authentication for critical function vulnerability in the Palo Alto Networks PAN-OS product.

Siemens Energy Exploit - SEC Consult published an exploit for four vulnerabilities in the Siemens Energy Omnivise T3000.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-3cc - subscription required.

Saturday, November 9, 2024

Review – Public ICS Disclosures – Week of 11-2-24

This week we have 13 vendor disclosures from Cisco, Hitachi (2), HPE (3), Moxa, Palo Alto Networks (2), QNAP, SEL, Sick, and WatchGuard. We have a vendor update from FortiGuard. Finally, we have 11 researcher reports for vulnerabilities in products from ABB and Delta Electronics (10).

Advisories

Cisco Advisory - Cisco published an advisory that describes a command injection vulnerability in their Unified Industrial Wireless Software.

Hitachi Advisory #1 - Hitachi published an advisory that discusses four vulnerabilities in multiple Hitachi products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses four vulnerabilities in their Cosminexus Developer's Kit for Java and Hitachi Developer's Kit products.

HPE Advisory #1 - HPE published an advisory that discusses the regreSSHion vulnerability. HPE provides a list of Cray products affected by the vulnerability.

HPE Advisory #2 - HPE published an advisory that discusses seven vulnerabilities (one with publicly available exploit) in their Unified OSS Console Assurance Monitoring (UOCAM) Software.

HPE Advisory #3 - HPE published an advisory that describes six vulnerabilities in their Aruba Networking Access Points.

Moxa Advisory - Moxa published an advisory that describes three vulnerabilities in their EDS-P510 Series products.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that discusses 77 vulnerabilities in their Cortex XDR agent product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses a claim of a remote code execution vulnerability via the PAN-OS management interface.

QNAP Advisory - QNAP published an advisory that describes an unidentified vulnerability in their QuRouter.

SEL Advisory - SEL published a new version notice for their Blueframe OS that reports that the latest version resolves two cybersecurity issues.

Sick Advisory - Sick published an advisory that discusses 10 vulnerabilities in their CDE-100 product. These are third-party vulnerabilities.

WatchGuard Advisory - WatchGuard published an advisory that describes an improper privilege management vulnerability in their Endpoint Protection product family.

Updates

FortiGuard Update - FortiGuard published an update for their FortiManager fgfmd daemon advisory that was originally published on October 23rd, 2024, and most recently updated on November 5th, 2024.

Researcher Reports

ABB Report - Zero Science published a report of an off-by-one error vulnerability (with publicly available exploit) in the ABB Cylon Aspect building energy management product.

Delta Reports - Zero Day Initiative published 10 reports describing vulnerabilities in the Delta DIAScreen, a component of the DIAStudio Smart Machine Suite.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-062 - subscription required.

 
/* Use this with templates/template-twocol.html */