Showing posts with label Splunk. Show all posts
Showing posts with label Splunk. Show all posts

Sunday, June 21, 2026

Review - Public ICS Disclosures – Week of 6-13-26 – Part 2

For Part 2 we have 11 additional vendor disclosures from Ingecon, Moxa (3), NI, Splunk (2), ThingsBoard, TP-Link, Turck, and Zyxel. Part 3 is coming tomorrow. 

Advisories  

Ingecon Advisory - INCIBE-CERT published an advisory that describes a use of broken or risky cryptographic algorithm vulnerability in the Ingecon EMS Board. 

Moxa Advisory #1 - Moxa published an advisory that describes a missing authentication vulnerability in their Serial Device Servers. 

Moxa Advisory #2 - Moxa published an advisory that describes two vulnerabilities in their Serial Device Servers. The vulnerabilities were reported by Remi ONNO of CS GROUP. 

Moxa Advisory #3 - Moxa published an advisory that describes an improper validation of specified type of input vulnerability in their Serial Device Servers. 

NI Advisory - NI published an advisory that describes seven vulnerabilities in their gRPC Device Server. 

Splunk Advisory #1 - Splunk published an advisory that describes an OS command injection vulnerability in their AI Toolkit. 

Splunk Advisory #2 - Splunk published an advisory that describes an OS command injection vulnerability in their AI Toolkit. 

ThingsBoard Advisory - JP-CERT published an advisory that describes a prototype pollution vulnerability in the ThingsBoard open-source IoT platform. 

TP-Link Advisory - TP-Link published an advisory that describes two OS command injection vulnerabilities in their TL-WR940N wireless router. 

Turck Advisory - CERT-VDE published an advisory that discusses two vulnerabilities (one with a publicly available exploit) in Turck Managed Ethernet Switches. 

Zyxel Advisory - Zyxel published an advisory that describes a stack-based buffer overflow vulnerability in their GS1900 series switches. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-c60 - subscription required. 

Friday, June 19, 2026

CISA Adds Splunk Vulnerability to KEV Catalog – 6-18-26

Yesterday, CISA announced that it had added a missing authentication for critical function vulnerability in the Splunk Enterprise product to its Known Exploited Vulnerabilities (KEV) catalog. Splunk previously disclosed the vulnerability on June 10th and provided new versions that mitigated the vulnerability. WatchTowr published a report on the vulnerability that included proof-of concept code last week. 

CISA is directing all federal agencies to mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA has set June 21st, 2026 as a compliance deadline. 

Monday, June 15, 2026

Review - Public ICS Disclosures – Week of 6-6-26 – Part 3

For Part 3 we have three additional vendor disclosures from Genetec (2) and VMware. There are bulk vendor updates from HP (5) and Siemens (10). There are four additional vendor updates from ABB, FortiGuard, Mitsubishi, and Moxa. We also have three researcher reports for vulnerabilities in products from Trane, Vertiv, and Splunk. Finally, we have four exploits for products from Palo Alto Networks (2), FortiGuard, and WatchGuard. 

Advisories  

Genetec Advisory #1 - Genetec published an advisory that describes an incorrect permission assignment for critical resource vulnerability in Genetec product installations deploying RabbitMQ. 

Genetec Advisory #2 - Genetec published an advisory that describes an insertion of sensitive information into a log file vulnerability in their Security Center main server installations. 

VMware Advisory - Broadcom published an advisory that describes three cross-site scripting vulnerabilities in the VMware Cloud Foundation Operations product. 

Bulk Vendor Updates  

HP (5) 

Siemens (10) 

Updates  

ABB Update - ABB published an update for their Freelance Security Lock advisory that was originally published on November 9th, 2025. 

FortiGuard Update FortiGuard published an update for their Sensitive 2FA Information advisory that was originally published on October 14th, 2025. 

Mitsubishi Update - Mitsubishi published an update for their Realtek Chips advisory that was originally published on March 24th, 2026. 

Moxa Update - Moxa published an update for their Diffie-Hellman Key Exchange Protocol advisory that was originally published on June 2nd, 2025. 

Researcher Reports  

Trane Report - Claroty published a report that describes five vulnerabilities in the Trane Tracer SC+ HVAC controller. 

Vertiv Report Claroty published a report that describes two vulnerabilities in the Vertiv’s Liebert IS-UNITY-DP network cards. 

Splunk Report WatchTowr published a report that describes a missing authentication for critical function vulnerability in the PostgreSQL Sidecar Service Endpoint in Splunk Enterprise. 

Exploits  

Palo Alto Networks Exploit #1 - Indoushka published a Metasploit module for a reliance on cookies without validation and integrity checking vulnerability in the PAN GlobalProtect product. 

Palo Alto Networks Exploit #2 - Gray Xploit published an exploit for a reliance on cookies without validation and integrity checking vulnerability in the PAN GlobalProtect product. 

FortiGuard Exploit Indoushka published a Metasploit module for an OS command injection vulnerability in the FortiGuard FortiSandbox product. 

WatchGuard Exploit - Cody Sixteen published an exploit for a logic error vulnerability in the WatchGuard Firebox product. 


For additional information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-81a - subscription required. 

 
/* Use this with templates/template-twocol.html */