Showing posts with label SolarWinds. Show all posts
Showing posts with label SolarWinds. Show all posts

Sunday, February 15, 2026

Review – Public ICS Disclosures – Week of 2-7-26 – Part 2

 For Part 2 we have five additional vendor disclosures from Arista, HPE, Supermicro, WAGO, and Yokogawa. There are ten vendor updates from Broadcom (3), CODESYS (2), HP, HPE, and Schneider (3). We also have three researcher reports for products from Sante, Linksys, and Solax. Finally, we have three exploits for products from FortiGuard, Palo Alto Networks, and SolarWinds.

Advisories

Arista Advisory - Arista published an advisory that describes six vulnerabilities in their Next Generation Firewall.

HPE Advisory - HPE published an advisory that discusses an improper handling of values vulnerability in their ProLiant DL/ML/XD, Synergy, Edgeline, MicroServer.

Supermicro Advisory - Supermicro published an advisory that discusses 11 vulnerabilities in multiple Supermicro products.

WAGO Advisory - CERT-VDE published an advisory that describes four vulnerabilities in the WAGO Industrial-Managed-Switch 0852-XXXX products.

Yokogawa Advisory - Yokogawa published an advisory that describes six vulnerabilities in their Vnet/IP Interface Package.

Updates

Broadcom Update #1 - Broadcom published an update for their Brocade Fabric OS advisory that was originally published on August 1st, 2023.

Broadcom Update #2 - Broadcom published an update for their Brocade Fabric OS advisory that was originally published on May 17th, 2017.

Broadcom Update #3 - Broadcom published an update for their rsynd advisory that was originally published on September 13, 2022.

CODESYS Update #1 - CODESYS published an update for their CODESYS Control advisory that was originally published on December 1st, 2025.

CODESYS Update #2 - CODESYS published an update for their CODESYS Control advisory that was originally published on December 1st, 2025.

HP Update - HP published an update for their LaserJet advisory that was originally published on November 13th, 2025, and most recently updated on December 10th, 2025.

HPE Update - HPE published an update for their Aruba Networking EdgeConnect advisory that was originally published on January 14th, 2026.

Schneider Update #1 - Schneider published an update for their EcoStruxure Power Operation advisory that was originally published on July 8th, 2025.

Schneider Update #2 - Schneider published an update for their EcoStruxure Foxboro DCS advisory that was originally published on December 9th, 2025.

Schneider Update #3 - Schneider published an update for their Uni-Telway Driver advisory that was originally published on February 11th, 2025, and most recently updated on January 13th, 2026.

Researcher Reports

Linksys Report - SySS Tech published a report that describes six vulnerabilities (with proof-of-concept code) in the Linksys MR9600 and MX4200 routers.

Sante Report - The Zero Day Initiative published a report that describes a buffer overflow vulnerability in the Sante DICOM Viewer Pro.

Solax Report - SEC Consult published a report that describes three vulnerabilities (with proof-of-concept code) in the Solax Power Pocket WiFi models.

Exploits

FortiGuard Exploit - Peter Gabaldon published an exploit for an exposure of sensitive information to an unauthorized actor vulnerability in the FortiGuard FortiGate product.

Palo Alto Networks Exploit - Indoushka published an exploit for four vulnerabilities in the Palo Alto Networks PAN-OS products.

 

For more information about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-c98 - subscription required.

Saturday, January 15, 2022

GAO Reports – Cybersecurity Response

This week, the GAO published a report on the federal government response to the nearly concurrent SolarWinds attack and organized exploits of the Microsoft Exchange vulnerabilities. This report looks at those response activities and outlines three National Security Council recommendations for improving responses to future cyberattack. An appendix provides separate timelines for the response to both incidents.

The accompanying highlight document identifies four lessons learned by responding agencies:

• Coordinating with the private sector led to greater efficiencies in agency incident response efforts,

• Providing a centralized forum for interagency and private sector discussions led to improved coordination among agencies and with the private sector,

• Sharing of information among agencies was often slow, difficult, and time consuming, and

• Collecting evidence was limited due to varying levels of data preservation at agencies.

The GAO reports that the NSC identified three areas that the government could take to take to prevent and improve the response to future incidents (pg 36):

• Align technology investments with operational priorities. The review identified that the federal government should invest resources to increase its capabilities to identify, detect, protect, and respond to significant cybersecurity incidents.

• Improve public-private engagement. The federal government should improve its coordination and information sharing with the private sector.

• Improve threat intelligence acquisition, sharing, and use among federal agencies. The federal government should improve information sharing with its partners.


Monday, February 22, 2021

Committee Hearings – Week of 2-21-21

This week, with both the House and Senate in session, there is a fairly normal hearing schedule on both sides of Capitol Hill. The Senate is concentrating on confirmation hearings, as would be expected. There is one cybersecurity hearing and two others that may touch on cybersecurity issues.

SolarWinds Breach

On Friday there will be a joint hearing of the House Oversight and Reform Committee and the House Homeland Security Committee on “Weathering the Storm: The Role of Private Tech in the SolarWinds Breach and Ongoing Campaign”. It will be a closed hearing and no witness list is currently available. There is a remote chance that there will be some discussion or at least questions about the impact of the Breach on industrial control system security, but we will probably never hear about them.

There will be more hearings on this topic, many of them public with lots of finger pointing and gnashing of teeth. Do not expect more than theater at this point.

Possible Cybersecurity Mentions

There are two hearings this week that may include some discussion about control system cybersecurity, but I will not be holding my breath. I call them out because of multiple mentions in the media about the possibility that the COVID relief bill could include some sort of funding for cybersecurity at water facilities.

This afternoon the House Budget Committee will hold a markup hearing on the “American Rescue Plan Act of 2021”. The text of the bill that the Committee will markup does not include any mention of cybersecurity. This is presumably one of the bills mentioned in last week’s post on TheCipherBrief that would provide funding for water facility cybersecurity. There is a $50 million mention (§3033) of funding for water facilities, but that is targeted to help pay overdue water bills. We might see something added in the markup, but not likely.

The second hearing will be conducted tomorrow by the Water Resources and Environment Subcommittee of the House Committee on Transportation and Infrastructure on “Building Back Better: The Urgent Need for Investment in America’s Wastewater Infrastructure”. No witness list is currently available. Again, there is a rather remote possibility that cybersecurity for these facilities could be mentioned in light of the recent drinking water hack in Florida.

 
/* Use this with templates/template-twocol.html */