Showing posts with label Santesoft. Show all posts
Showing posts with label Santesoft. Show all posts

Tuesday, August 12, 2025

Review – 5 Advisories and 2 Updates Published – 8-12-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Aveva, Schneider Electric, Johnson Controls, and Ashlar-Vellum. The also published a medical device security advisory for products from Santesoft. Finally, they updated two control system advisories for products from End-of-Train and Megasys.

Schneider published four additional advisories and five updates today. Unless covered by CISA on Thursday, I will address them in my Public ICS Disclosure posts this weekend.

Advisories

AVEVA Advisory - This advisory describes two vulnerabilities in the AVEVA PI Integrator.

Schneider Advisory - This advisory describes five vulnerabilities in the Schneider EcoStruxure Power Monitoring Expert.

Johnson Controls Advisory - This advisory describes six vulnerabilities in multiple iStar products from Johnson Controls.

Ashlar-Vellum Advisory - This advisory describes four vulnerabilities in multiple products from Ashlar-Vellum.

Santesoft Advisory - This advisory describes five vulnerabilities in the Santesoft Sante PACS Server.

Updates

End-of-Train Update - This update provides additional information on the remote linking protocol advisory that was originally published on July 10th 2025.

MegaSys Update - This update provides additional information on the Telenium Online Web Application advisory that was originally published on September 19th, 2024.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-and-2-updates-published-2b9 - subscription required.

Thursday, May 29, 2025

Review – 5 Advisories Published – 5-29-25

Today CISA’s NCCIC-ICS published four control system security advisories for products from Instantel, Consilium Safety, and Siemens (2). They also published a medical device security advisory for products from Santsoft.

Advisories

Instantel Advisory - This advisory describes a missing authentication for critical function vulnerability in the Instantel Micromate monitoring device.

Consilium Advisory - This advisory describes two vulnerabilities in the Consilium S5000 Fire Panel.

Siemens Advisory #1 - This advisory describes an out-of-bounds read vulnerability in the Siemens SiPass integrated products.

Siemens Advisory #2 - This advisory describes an improper verification of cryptographic signature vulnerability in the Siemens SiPass integrated products.

Santesoft Advisory - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante DICOM Viewer Pro.

 

For more information on these advisories, including links to researcher reports, as well as a down-the-rabbit-hole look at the Consilium vulnerability, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-published-5-29-25 - subscription required.

Thursday, March 20, 2025

Review – 5 Advisories Published – 3-20-25

Today CISA published four control systems security advisories for products from SMA Solar Technology, Siemens, and Schneider Electric (2). The also published a medical device security advisory for products from Santesoft.

Advisories

SMA Advisory - This advisory describes an unrestricted upload of file with dangerous type vulnerability in the SMA Sunny Portal.

Siemens Advisory - This advisory describes an improper restriction of operations within the bounds of a memory buffer vulnerability in the Siemens Simcenter Femap product.

Schneider Advisory #1 - This advisory describes three improper input validation vulnerabilities in the Schneider Enerlin’X IFE and eIFE products.

Schneider Advisory #2 - This advisory describes an improper privilege management vulnerability in the Schneider EcoStruxure Process Expert products.

Santesoft Advisory - This advisory describes an out-of-bounds write vulnerability in the Santesoft Sante DICOM Viewer Pro.

 

For more information on these advisories, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/5-advisories-published-3-20-25 - subscription required.

Tuesday, March 5, 2024

Review – 2 Advisories and 1 Update Published – 3-5-24

Today, CISA’s NCCIC-ICS published a control system security advisory for products from Nice and a medical device control system security advisory for products from Santesoft. They also updated a security advisory for products from Integration Objects. CISA also added a surveillance product vulnerability to their Known Exploited Vulnerabilities (KEV) catalog for products from Sunhillo.

Advisories

Nice Advisory - This advisory describes 12 vulnerabilities in the Nice Linear eMerge E3-Series access control products.

Santesoft Advisory - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante FFT Imaging product.

Updates

Integration Update - This update provides additional information on the OPC UA Server Toolkit advisory that was originally published on January 16th, 2024.

KEV

New KEV Lising - CISA added CVE-2021-36380 Sunhillo SureLine OS command injection vulnerability to the KEV catalog.

 

For more information about these advisories, including links to researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-and-1-update-published-c77 - subscription required.

Tuesday, February 27, 2024

Review – 2 Advisories Published – 2-27-24

Today, CISA’s NCCIC-ICS published a control system security advisories for products from Mitsubishi Electric and a medical device security advisory for products from Santesoft.

Advisories

Mitsubishi Advisory - This advisory describes an insufficient resources pool vulnerability in the Mitsubishi MELSEC iQ-F Series compact control platform.

Santesoft Advisory - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante DICOM viewer.

 

For more details about these advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-2-27-24 - subscription required.

Thursday, October 12, 2023

Review – 18 Advisories and 1 Updates Published

Today, CISA’s NCCIC-ICS published 16 control system security advisories for products from Schneider, Advantech, Hikvision, Mitsubishi, Weintek, and Siemens (11) and two medical device security advisories for products from Santesoft. They also updated an advisory for products from PTC.

Siemens published one additional advisory (and 11 updates) on Tuesday that were not covered here. CISA no longer updates their Siemens advisories. I will discuss all them this weekend in my Public ICS Disclosure blog post.

Advisories

Schneider Advisory - This advisory describes a missing authentication for critical function vulnerability in the Schneider Interactive Graphical SCADA System (IGSS).

Advantech Advisory - This advisory describes an exposure of sensitive information to an unauthorized actor vulnerability in the Advantech WebAccess product.

Hikvision Advisory - This advisory describes two vulnerabilities in the Hikvision Access Control and Intercom Products.

Mitsubishi Advisory - This advisory describes an improper authentication vulnerability in the Mitsubishi MELSEC-F Series main modules.

Weintek Advisory - This advisory describes three vulnerabilities in the Weintek cMT3000 CMI Web CGI.

Mendix Advisory - This advisory describes an observable discrepancy vulnerability in the Siemens Mendix Forgot Password Module.

Tecnomatix Advisory - This advisory describes seven vulnerabilities in the Siemens Tecnomatix Plant Simulation product.

SICAM Advisory #1 - This advisory describes a use of hard-coded credentials vulnerability in the Siemens CP-8050 and CP-8031 master modules.

SICAM Advisory #2 - This advisory describes an incorrect permission assignment for a critical resource vulnerability in the Siemens SICAM PAS/PQS.

SICAM Advisory #3 - This advisory describes a path traversal advisory vulnerability in the Siemens SICAM A8000 CP-8031 and CP-8050 master modules.

SINEC Advisory - This advisory describes two vulnerabilities in the Siemens SINEC NMS.

RUGGEDCOM Advisory - This advisory discusses seven vulnerabilities in the Siemens RUGGEDCOM APE1808.

Simcenter Advisory - This advisory describes a code injection vulnerability in the Siemens Simcenter Amesim product.

Xpedition Advisory - This advisory describes a stack-based buffer overflow vulnerability in the Siemens Xpedition Layout Browser.

SCALANCE Advisory - This advisory discusses thirteen vulnerabilities in the Siemens SCALANCE W1750D.

SIMATIC Advisory - This advisory describes two vulnerabilities in the Siemens SIMATIC CP products.

Santesoft Advisory #1 - This advisory describes an out-of-bounds read vulnerability in the Santesoft Sante FFT Imaging.

Santesoft Advisory #2 - This advisory describes two vulnerabilities in the Santesoft Sante DICOM Viewer Pro.

Updates

PTC Update - This update provides additional information on an advisory that was originally published on August 31st, 2023.

 

For more information on these advisories, including lists of missing vulnerabilities, links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/18-advisories-and-1-updates-published - subscription required.

Sunday, May 1, 2022

Review – Public ICS Disclosures – Week of 4-23-22 – Part 2

This week for Part 2 we have two additional vendor disclosures from Dell and Johnson Controls. There are also seven vendor updates from Bayer, FANUC, HP, Palo Alto Networks, QNAP, Siemens, and Yokogawa. Finally, there are four researcher reports for products from Delta Industrial (3) and Santesoft,

Dell Advisory - Dell published an advisory discussing an infinite loop vulnerability in their Wyse ThinOS products.

Johnson Controls Advisory - Johnson Controls published an advisory discussing the SpringShell vulnerabilities.

Bayer Update - Bayer published an update for their Log4Shell and Access:7 advisory that was originally published on March 8th, 2022.

FANUC Update - FANUC published an update for their ROBOGUIDE advisory that was originally published on April 8th, 2022.

HP Update - HP published an update for their Expat Library advisory for their PCoIP products that was originally published on April 11th, 2022.

Johnson Controls Update - Johnson Controls published an update for their SpringShell advisory that was originally published on April 19th, 2022.

Palo Alto Networks Update - Palo Alto Networks published an update for their Cortex XDR Agent advisory that was originally published on April 13th, 2022

QNAP Update - QNAP published an update for their Apache HTTP server advisory that was originally published on April 20th, 2022.

Siemens Update - Siemens published an update for their SpringShell advisory that was originally published on April 19th, 2022.

Yokogawa Update - Yokogawa published an update for their Centum advisory that was originally published on January 14th, 2022 and most recently updated on March 16th, 2022.

Delta Reports - The Zero Day Initiative published three 0-day reports about vulnerabilities from Delta Industrial.

Santesoft - ZDI published a report describing an out-of-bounds write vulnerability in the Santesoft DICOM Viewer Pro.

 

For more details about these advisories and updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-239  - subscription required.

 
/* Use this with templates/template-twocol.html */