Showing posts with label Synology. Show all posts
Showing posts with label Synology. Show all posts

Saturday, July 20, 2024

Review – Public ICS Disclosures – Week of 7-13-24

This week we have three vendor disclosures on the regreSSHion vulnerability from Bosch, Broadcom, HMS  We have 14 additional vendor disclosures from ABB, Dell, Fujitsu, Hitachi, HP (4), HPE (3), Rockwell (2), and Wireshark. There are also five vendor updates from BD and HPE (4). Finally, we have four researcher reports about vulnerabilities in products from Asus, Synology, and Unitronics (2).

RegreSSHion Advisories

Bosch published an advisory that lists affected products and fixed versions.

Broadcom published an advisory that lists the products that are not affected.

HMS published an advisory that lists the affected products and announces that fixes have been applied.

Advisories

ABB Advisory - ABB published an advisory that describes an unquoted search path or element vulnerability in their Mint Workbench product.

Dell Advisory - Dell published an advisory that lists a large number (nope, I am not counting them all) of 3rd party vulnerabilities in their ThinOS product.

Fujitsu Advisory - JP-CERT published an advisory that describes a path traversal vulnerability in the Fujitsu Network Edgiot GW1500 product.

Hitachi Advisory - Hitachi published an advisory that discusses 42 vulnerabilities in their Disc Array Systems products.

HP Advisory #1 - HP published an advisory that describes a buffer overflow vulnerability in multiple desk top computers.

HP Advisory #2 - HP published an advisory that describes two privilege escalation vulnerabilities in their display control software.

NOTE: The HP Security Bulletins page lists two additional advisories (here and here), but neither page currently opens.

HPE Advisory #1 - HPE published an advisory that describes a remote bypass of a security restriction vulnerability in their 3PAR Service Processor Software.

HPE Advisory #2 - HPE published an advisory that discusses 17 vulnerabilities (one with known exploits) in their Unified OSS Console Assurance Monitoring (UOCAM) product.

HPE Advisory #3 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML/XL, Synergy, Edgeline and Alletra Servers.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their SequenceManager Server.

Advisory #2 - Rockwell published an advisory that describes an improper input validation vulnerability in their 5015 – AENFTXT product.

Wireshark Advisory - Wireshark published an advisory that describes a packet injection vulnerability in their SPRT dissector product.

Updates

BD Update - BD published an update for their Third-Party ESET advisory that was originally published on March 29th, 2024.

HPE Update #1 - HPE published an update for their Intel Thunderbolt Driver advisory that was originally published on May 14th, 2024 and most recently updated on June 17th, 2024.

HPE Update #2 - HPE published an update for their Intel PROSet/Wireless WiFi and Bluetooth advisory that was originally published on May 14th, 2024 and most recently updated on June 17th, 2024.

HPE Update #3 - HPE published an update for their Intel Chipset Device Software advisory that was originally published on June 28th, 2024.

HPE Update #4 - HPE published an update for their Intel 2024.1 IPU - Chipset Software advisory that was originally published on March 13th, 2024 and most recently updated on April 10th, 2024.

Researcher Reports

Asus Report - BugProve published a report describing a stack-based buffer overflow vulnerability in the Asus RT-AC87U router.

Synology Report - Claroty published a report that describes a classic buffer overflow vulnerability in the Synology BC 500 IP camera.

Unitronics Reports - Claroty published two reports about individual vulnerabilities in the Unitronics Vision Plc.

 

For more information about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-3e2 - subscription required.

Sunday, July 14, 2024

Review – Public ICS Disclosures – Week of 7-6-23 – Part 2

For Part 2 this week, we have 24 vendor updates from Schneider (3) and Siemens (21). There are three researcher reports for products from SonicWall, Synology, and TP-Link. There was one exploit published for products from VMware. Finally, we have an article from Siemens that should be of interest.

Updates

Schneider Update #1 - Schneider published an update for their SAGE RTU advisory that was originally published on June 11th, 2024.

Schneider Update #2 - Schneider published an update for their EcoStruxure Control Expert advisory that was originally published on February 13th, 2024.

Schneider Update #3 - Schneider published an update for their Modicon Controllers advisory that was originally published on December 8th, 2020 and most recently updated on February 13th, 2020.

Siemens Update #1 - Siemens published an update for their SIMATIC IPCs advisory that was originally published on September 12th, 2023 and most recently updated on November 14th, 2023.

Siemens Update #2 - Siemens published an update for their Industrial Products advisory that was originally published on May 14th, 2024.

Siemens Update #3 - Siemens published an update for their RUGGEDCOM APE1808 devices advisory that was originally published on March 12th, 2024 and most recently updated on June 11th, 2024.

Siemens Update #4 - Siemens published an update for their PROFINET Devices advisory that was originally published on February 11th, 2020 and most recently updated on April 11th, 2024.

Siemens Update #5 - Siemens published an update for their SIMATIC WinCC advisory that was originally published on February 13th, 2024 and most recently updated on June 11th, 2024.

Siemens Update #6 - Siemens published an update for their RUGGEDCOM APE1808 devices advisory that was originally published on April 19th, 2024.

Siemens Update #7 - Siemens published an update for their SIMATIC WinCC advisory that was originally published on April 9th, 2024.

Siemens Update #8 - Siemens published an update for their n OpenSSL (CVE-2022-0778) advisory that was originally published on June 14th, 2022, and most recently updated on May 14th, 2024.

Siemens Update #9 - Siemens published an update for their OPC UA Implementation advisory that was originally published on September 12th, 2023, and most recently updated on June 11th, 2024.

Siemens Update #10 - Siemens published an update for their Industrial Products using Intel CPUs advisory that was originally published on February 14th, 2023, and most recently updated on August 8th, 2023.

Siemens Update #11 - Siemens published an update for their SegmentSmack advisory that was originally published on April 14th, 2020, and most recently updated on May 14th, 2024.

Siemens Update #12 - Siemens published an update for their SINEMA Remote Connect Server advisory that was originally published on June 14th, 2022.

Siemens Update #13 - Siemens published an update for their PROFINET Devices advisory that was originally published on October 8th, 2018, and most recently updated on May 9th, 2023.

Siemens Update #14 - Siemens published an update for their RUGGEDCOM APE1808 devices advisory that was originally published on April 9th, 2024, and most recently updated on May 14th, 2024.

Siemens Update #15 - Siemens published an update for their PROFINET Stack advisory that was originally published on April 12th, 2022 and most recently updated on June 11th, 2024.

Siemens Update #16 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2023, and most recently updated on June 11th, 2024.

Siemens Update #17 - Siemens published an update for their SNMP Interface advisory that was originally published on November 23, 2017, and most recently updated on February 8th, 2022.

Siemens Update #18 - Siemens published an update for their TIM 1531 IRC advisory that was originally published on June 11th, 2024.

Siemens Update #19 - Siemens published an update for their PROFINET DCP Implementation advisory that was originally published on May 8th, 2017, and most recently updated on February 8th, 2022.

Siemens Update #20 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on April 9th, 2024 and most recently updated on May 14th, 2024.

Siemens Update #21 - Siemens published an update for their SINEC NMS advisory that was originally published on October 10th, 2023.

Researcher Reports

SonicWall Report - SSD published a report that describes two vulnerabilities in the SonicWall SMA100 platform.

Synology Report - Claroty published a report that describes a classic buffer overflow vulnerability in the Synology BC500 cameras.

TP Link Report - Claroty published a report that describes three vulnerabilities in the TP-Link ER605 routers.

Exploits

VMware Exploit - Sina Kheirkhah published an exploit for a command injection vulnerability (that is listed in the CISA Known Exploited Vulnerability Catalog) in the VMware Aria Operations product.

Articles

Siemens Article - Siemens published an article on “RADIUS Advisory and the benefits of ProductCERT’s improved formats”.

 

For additional information about these disclosures, including a brief summary of the changes made in the updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-86f - subscription required.

Saturday, July 13, 2024

Review – Public ICS Disclosures – Week of 7-6-23 – Part 1

This week we have eight vendor disclosures about the Blast-Radius and RegreSSHion vulnerabilities. We have 25 additional vendor disclosures from BD, FortiGuard (3), Hitachi, Moxa, OPC Foundation, Palo Alto Networks (5), Pepperly+Fuchs (2), Philips, Schneider (4), SEL, and VMware (7).

Blast-RADIUS Advisories

Cisco published an advisory that provides a list of products currently under review as being potentially affected.

HPE published an advisory that provides a list of Aruba Networking products affected.

Palo Alto Networks published an advisory that provides a list of affected products and provides work arounds.

WatchGuard published an advisory that provides a list of products that they are investigating with regards to this vulnerability.

RegreSSHion Advisories

Cisco published an update that updated the lists of affected products, unaffected products, and products currently under review.

HMS published an advisory that provides a list of affected products and reports that: “All servers have been updated on 10/07/2024. No further actions are needed.”

Philips published an advisory that reports that none of their products are affected.

Synology published an advisory that reports that none of their products are affected.

Advisories

BD Advisory - BD published an advisory that discusses an improper privilege management vulnerability in multiple BD products.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an improper access control vulnerability in their FortiExtender authentication component.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an incorrect parsing of numbers with different radices vulnerability in their FortiOS and FortiProxy IP address validation feature.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiOS and FortiProxy's web SSL VPN UI.

Hitachi Advisory - Hitachi published an advisory that discuses 70 vulnerabilities in their Disk Array Systems. These are third-party (Microsoft) vulnerabilities.

Moxa Advisory - Moxa published an advisory that discusses a use after free vulnerability (that is listed in CISA’s Known Exploited Vulnerabilities Catalog) in multiple Moxa products.

OPC Foundation - The OPC Foundation published an advisory that describes an allocation of resources without limits or throttling vulnerability in their UA-.NETStandard product.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes a hard-coded password vulnerability in their Expedition VM product.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes an improper input validation vulnerability in their PAN-OS product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that describes an improper verification of cryptographic signature vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #4 - Palo Alto Networks published an advisory that describes an unrestricted upload of file with dangerous type vulnerability in their PAN-OS products.

Palo Alto Networks Advisory #5 - Palo Alto Networks published an advisory that describes a missing authentication for critical function vulnerability in the Network Expedition product.

Pepperl+Fuchs Advisory #1 - CERT-VDE published an advisory that discusses a use after free vulnerability in their Smart-Ex 02 and Smart-Ex 03 products.

Pepperl+Fuchs Advisory #2 - CERT-VDE published an advisory that describes two vulnerabilities in the Pepperl+Fuchs OIT-XXXX products.

Philips Advisory - Philips published an advisory that discusses a TeamViewer vulnerability. Philips reports that none of their products are affected.

Schneider Advisory #1 - Schneider published an advisory that describes an exposure of sensitive information to an unauthorized actor vulnerability in their Wiser Home Controller WHC-5918A.

Schneider Advisory #2 - Schneider published an advisory that describes three vulnerabilities in their Foxboro DCS Core Control Services.

Schneider Advisory #3 - Schneider published an advisory that describes a path traversal vulnerability in their EcoStruxure Foxboro SCADA FoxRTU Station.

Schneider Advisory #4 - Schneider published an advisory that describes a cross-site scripting vulnerability in their Modicon Controllers.

SEL Advisory - SEL published a new version notice for their SEL-5052 Server Software that includes descriptions of cybersecurity fixes.

VMware Advisory #1 - Broadcom published an advisory that describes an SQL injection vulnerability in the VMware Aria Automation product.

VMware Advisories #2 thru #7 - Broadcom re-published six VMware advisories in the Broadcom format.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-c55 - subscription required.

Sunday, February 4, 2024

Review – Public ICS Disclosures – Week of 1-27-24 – Part 2

For Part 2 we have ten additional vendor disclosures from Schneider, SE-elektronic, Sharp, Sick, Splunk (3), Synology, Trumpf, and Zyxel. We also have five researcher reports for vulnerabilities in products from TELSAT (4) and NAVBLUE. Finally, we have six exploits for products from Electrolink.

Advisory

Schneider Advisory - Schneider published an advisory that discusses the recent cyberattack on their Sustainability Business Division.

SE-elektronic Advisory - Incibe-CERT published an advisory that describes two vulnerabilities in the SE-elektronic E-DDC3.3 automation station.

Sharp Advisory - JP-CERT published an advisory that describes seven vulnerabilities in the Sharp Energy Management Controller with Cloud Services product.

Sick Advisory - Sick published an advisory that discuss a deserialization of untrusted data vulnerability that is listed in CISA’s Known Exploited Vulnerability (KEV) catalog.

Splunk Advisory #1 - Splunk published an advisory that describes an insertion of sensitive information in log files vulnerabilities in their Splunk Add-on Builder product.

Splunk Advisory #2 - Splunk published an advisory that describes an insertion of sensitive information in log files vulnerabilities in the Splunk Add-on Builder product.

Splunk Advisory #3 - Splunk published an advisory that discusses two vulnerabilities in the Splunk Add-on Builder.

Synology Advisory - Synology published an advisory that describes an open redirect vulnerability in their DiskStation Manager (DSM) product.

Trumpf Advisory - CERT-VDE published an advisory that discusses four classic buffer overflow vulnerabilities in the Trumpf Oseon and TruTops Fab products.

Zyxel Advisory - Zyxel published an advisory that describes an OS command injection vulnerability in their NAS products.

Researcher Reports

TELSAT Reports - Zero Science published four reports about individual vulnerabilities in the TELSAT marKoni FM Transmitter.

NAVBLUE Report - Pentest Partners published a report describing the lack of an active application transport security (ATS) control in the NAVBLUE Flysmart+ Manager electronic flight bag.

Exploits

Electrolink Exploit #1 - Liquid Worm published an exploit for a credential exposure vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #2 - Liquid Worm published an exploit for a credential exposure vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #3 - Liquid Worm published an exploit for an authentication bypass vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #4 - Liquid Worm published an exploit for a remote authentication vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #5 - Liquid Worm published an exploit for a remote denial-of-service vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #6 - Liquid Worm published an exploit for a MPFS image remote code execution vulnerability in the Electrolink FM/DAB/TV Transmitter.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-560 - subscription required.

Saturday, January 20, 2024

Review – Public ICS Disclosures – Week of 6-13-24

This week we have 12 vendor disclosures from Broadcom, Dahua, Hitachi (4), HP, HPE, Insyde, SonicWall, Three R Solutions, and VMware. There are two vendor updates from Palo Alto Networks and Synology. We also have two researcher reports that describe vulnerabilities in products from Synology and Korenix.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses an out-of-bounds write vulnerabilities that is listed in the CISA Known Exploited Vulnerabilities Catalog in multiple Brocade products.

Dahua Advisory - JP-CERT published an advisory that describes an authentication bypass vulnerability in multiple Dahua products.

Hitachi Advisory #1 - Hitachi published an advisory that describes two vulnerabilities in their Device Manager.

Hitachi Advisory #2 - Hitachi published an advisory that discusses an allocation of resources without throttling or limits vulnerability in their Tuning Manager product.

Hitachi Advisory #3 - Hitachi published an advisory that discusses an out-of-bounds write vulnerability in multiple Hitachi products.

Hitachi Advisory #4 - Hitachi published an advisory that describes an incorrect default permissions vulnerability in their Tuning Manager product.

HP Advisory - HP published an advisory that discusses seven vulnerabilities in multiple HP products.

HPE Advisory - HPE published an advisory that discusses eight vulnerabilities in their  HP-UX Apache Web Server products.

Insyde Advisory - Insyde published an advisory that discusses nine vulnerabilities in their EDK2 NetworkPkg IP stack

SonicWall Advisory - SonicWall published an advisory that describes a stack-based buffer overflow vulnerability in their Capture Client and NetExtender Client Windows products.

Three R Solutions Advisory - JP-CERT published an advisory that describes an insufficient technical documentation vulnerability in the Three R Solutions Thermal camera TMC series products.

VMware Advisory - VMware published an advisory that describes a missing access control vulnerability in their Aria Automation products.

Updates

Palo Alto Networks Update - Palo Alto Networks published an update for their Terrapin-Attack vulnerability that was originally published on January 8th, 2024.

Synology Update - Synology published an update for their DiskStation Manager advisory that was originally published on January 9th, 2024.

Researcher Reports

Synology Report - Claroty published a report describing an inadequate data validation vulnerability in the Synology RT6600ax routers.

Korenix Report - CyberDanube published a report describing two vulnerabilities in the Korenix JetNet Series industrial switch.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-7a6 - subscription required. 

Saturday, December 2, 2023

Review – Public ICS Disclosures – Week of 11-25-23

This week we have 15 vendor disclosures from Festo, Hitachi Energy (3), HPE, Medtronic, Red Lion, Ruckus, SEL, Sierra Wireless, Synology (2), WatchGuard, and Zyxel (2). There are nine vendor updates from Hitachi Energy (7), HPE, and VMware. There is also a researcher report describing vulnerabilities in products from SEL. Finally, we have two exploits for products from Loytec.

Advisories

Festo Advisory - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in multiple Festo products.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory that describes three vulnerabilities in their RTU500 series products.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory that discusses an off-by-one error vulnerability in their SDM600 series products.

Hitachi Energy Advisory #3 - Hitachi Energy published an advisory that describes an improper input validation vulnerability in their s Relion® 670/650/SAM600-IO series products.

HPE Advisory - HPE published an advisory that discusses two improper initialization vulnerabilities in their Cray Servers and ProLiant DL/XL Servers.

Medtronic Advisory - Medtronic published an advisory that discusses two vulnerabilities in their Mainspring Data Express, and Vital Sync Virtual Patient Monitoring Platform products.

Red Lion Advisory - Red Lion published an advisory that describes an improper neutralization of special elements vulnerability in their Crimson 3.2 software.

Ruckus Advisory - Ruckus published an advisory that describes a cross-site scripting vulnerability in multiple Ruckus products.

SEL Advisory - SEL published a cybersecurity notice for their Blueframe OS product.

Sierra Wireless Advisory - Sierra Wireless published an advisory that describes eight vulnerabilities in their ALEOS, the operating system used in certain Sierra Wireless AirLink Routers.

Synology Advisory #1 - Synology published an advisory that describes an arbitrary code execution vulnerability in their Synology Camera BC500 and Synology Camera TC500.

Synology Advisory #2 - Synology published an advisory that describes a man-in-the-middle vulnerability in their Router Manager.

WatchGuard Advisory - WatchGuard published an advisory that discusses the heap buffer overflow in libwebp WebP Codec vulnerability that is listed in the CISA Known Exploited Vulnerabilities catalog.

Zyxel Advisory #1 - Zyxel published an advisory that describes nine vulnerabilities in multiple Zyxel firewall and access point (AP) products.

Zyxel Advisory #2 - Zyxel published an advisory that describes the six vulnerabilities in their NAS326 and NAS542 products.

Updates

Hitachi Energy Updates - Hitachi Energy published seven updates for the purpose of rebranding the advisories from “Hitachi/ABB Power Grids” to “Hitachi Energy”.

HPE Update - HPE published an update for their OneView advisory that was originally published on October 25th, 2023.

VMware Update - VMware published an update for their Cloud Director Appliance advisory that was originally published on November 14th, 2023.

Researcher Reports

SEL Report - Nozomi Networks published a report describing five vulnerabilities in the SEL-451 substation bay control  device.

Exploits

Loytec Exploit #1 - Chizuru Toyama published an exploit for three vulnerabilities in the Loytec LINX Configurator.

Loytec Exploit #2 - Chizuru Toyama published an exploit for a four vulnerabilities in the Loytec LINX Configurator.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-7e2 - subscription required.

Saturday, October 21, 2023

Review – Public ICS Disclosures – Week of 10-14-23 – Part 2

For Part 2 we have 43 more vendor disclosures from Moxa, NI, Philips, QNAP, Rockwell Automation, Ruckus Wireless, Synology, Tanzu (31), VMware (2), WAGO, and Yokogawa. We have three vendor updates for products from Broadcom, HPE, and Moxa. Finally, we have two researcher reports for vulnerabilities in products from Synology and Tideworks.

Advisories

Moxa Advisory #1 - Moxa published an advisory that describes eight vulnerabilities in their TN-5900 and TN-4900 Series Web Server.

NI Advisory - NI published an advisory that describes a stack-based buffer overflow vulnerability in their NI System Configuration product.

Philips Advisory - Philips published an advisory that discusses the Cisco IOS XE Software Web UI privilege escalation vulnerability that was recently added to CISA’s Known Exploited Vulnerabilities Catalog.

QNAP Advisory - QNAP published an advisory that describes an OS command injection vulnerability in their QUSBCam2.

Rockwell Advisory - Rockwell published an advisory that discusses Cisco IOS XE Software Web UI privilege escalation vulnerability.

Ruckus Advisory - Ruckus published an advisory that describes a cross-site scripting vulnerability in their Cloudpath product.

Synology Advisory - Synology published an advisory that discusses the HTTP2-Rapid-Reset vulnerability.

Tanzu Advisories - Tanzu published 31 advisories that discuss various third-party vulnerabilities.

VMware Advisory #1 - VMware published an advisory that describes two vulnerabilities in their Aria Operations for Logs product.

VMware Advisory #2 - VMware published an advisory that describes three vulnerabilities in their Workstation Pro/Player.

WAGO Advisory - CERT-VDE published an advisory that describes an externally controlled reference to a resource in another sphere.

Updates

Broadcom Update - Broadcom published an update for their Product Security Incident Response Team Contact Information advisory that was originally published on February 7th, 2023.

HPE Update - PE published an update for their OneView advisory that was originally published on September 14th, 2023.

Moxa Update - Moxa published an update for their TN-5900 and TN-5400 advisory that was originally published August 16th, 2023, and most recently updated on September 4th, 2023.

Reports

Synology Report - Claroty published a report that describes a use of insufficiently random values vulnerability in the Synology DiskStation Manager (DSM).

Tideworks Report - Black Lantern Security published a report that describes two vulnerabilities in the Tideworks Forecast product.

 

For more information about these disclosures, including links to 3rd party advisories, and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-22c - subscription required.

Saturday, October 14, 2023

Review – Public ICS Disclosures – Week of 10-7-23 – Part 1

This week we have 19 vendor disclosures from Cisco, FortiGuard (5), Insyde, Palo Alto Networks (3), Pilz, QNAP (4), Rockwell Automation, Sick, Synology, and Zebra Technologies. There is a vendor update from Cisco. Finally, for Part 1 anyway, we have 22 researcher reports for products from Peplink (4), SoftEther (9), and Yifan (9).

For Part 2 we will have disclosures and updates from Schneider and Siemens and five control system exploits.

Advisories

Cisco Advisory - Cisco published an advisory that discusses the recently announced SOCKS5 handshake vulnerability.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an access control vulnerability in their FortiOS products.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes an information disclosure vulnerability in their FortiOS products.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes an improper authorization vulnerability in their FortOS products.

FortiGuard Advisory #4 - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiOS products.

FortiGuard Advisory #5 - FortiGuard published an advisory that describes a use after free vulnerability in their FortiOS and FortiProxy products.

Insyde Advisory - Insyde published an advisory that describes an incorrect information reporting vulnerability in their TrEEConfigDriver.

Palo Alto Networks Advisory # 1 - Palo Alto Networks published an advisory that discusses the Rapid Reset vulnerability.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that describes a clear-text storage of sensitive information vulnerability in their Cortex XSOAR product.

Palo Alto Networks Advisory #3 - Palo Alto Networks published an advisory that discusses the announced SOCKS5 handshake vulnerability.

Pilz Advisory - CERT VDE published an advisory that discusses two vulnerabilities in multiple Pilz products.

QNAP Advisory #1 - QNAP published an advisory that describes three vulnerabilities in their Video Station product.

QNAP Advisory #2 - QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes a path traversal vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #4 - QNAP published an advisory that describes an OS command injection vulnerability in their Container Station product.

Rockwell Advisory - Rockwell published an advisory that describes an improper input validation vulnerability in their FactoryTalk Linx product.

Sick Advisory - Sick published an advisory that describes nine vulnerabilities in their Application Processing Unit.

Synology Advisory - Synology published an advisory that discusses the Rapid Reset Vulnerability.

Zebra Advisory - INCIBE CERT published an advisory that describes an authentication bypass using an alternate path or channel in the Zebra  ZTC ZT410-203dpi ZPL printers.

Updates

Cisco Update - Cisco published an update for their Adaptive Security Appliance Software advisory that was originally published on September 6th, 2023, and most recently updated on September 29th, 2023.

Researcher Reports

Peplink Reports - Cisco Talos published four reports about vulnerabilities in the Peplink Surf SOHO HW1 routers.

SoftEther Reports - CISCO Talos published 9 reports on vulnerabilities in the VPN product from SoftEther.

Yifan Reports - Cisco Talos published nine reports about vulnerabilities in the Yifan YF325 industrial cellular router.

 

For more details about these disclosures, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-a73 - subscription required.

Saturday, September 30, 2023

Review – Public ICS Disclosures – Week of 9-23-23

This week we have 15 vendor disclosures from Belden, Hitachi (5), Hitachi Energy, HPE, Panasonic, Pilz, Rockwell (2), SEL, Synology, and VMware. There are three vendor updates from Broadcom.

Advisories

Belden Advisory - Belden published an advisory that discusses 14 vulnerabilities in a number of their Hirschmann products.

Hitachi Advisory #1 - Hitachi published an advisory that discusses an observable discrepancy vulnerability in their Command Suite and Configuration Manager products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses an integer overflow or wraparound vulnerability in their Cosminexus HTTP Server.

Hitachi Advisory #3 - Hitachi published an advisory that discusses an integer overflow or wraparound vulnerability in their Cosminexus HTTP Server.

Hitachi Advisory #4 - Hitachi published an advisory that discusses an integer overflow or wraparound vulnerability in their Cosminexus HTTP Server.

Hitachi Advisory #5 - Hitachi published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their Cosminexus HTTP Server.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses 14 vulnerabilities in their AFS65x, AFS67x, AFR67x and AFF66x series Products.

HPE Advisory - HPE published an advisory that describes two authentication bypass vulnerabilities in their OneView product.

Panasonic Advisory - JP-CERT published an advisory that describes two vulnerabilities in the Panasonic KW Watcher product.

Pilz Advisory - Pilz published an advisory that discusses five vulnerabilities in multiple Pilz products.

Rockwell Advisory #1 - Rockwell published an advisory that discusses five vulnerabilities (listed in CISA’s KEV) in their Connected Components Workbench.

Rockwell Advisory #2 - Rockwell published an advisory that describes an out-of-bounds write vulnerability in their Logix Communication Modules.

SEL Advisory - SEL published a software update for their Configuration API which addressed three cybersecurity vulnerabilities and included two cybersecurity enhancements.

Synology Advisory - Synology published an advisory that describes a security bypass vulnerability in their Synology Router Manager (SRM).

VMware Advisory - VMware published an advisory that describes a privilege escalation vulnerability in their Aria Operations product.

Wago Advisory - CERT-VDE published an advisory that describes two vulnerabilities in their Codemeter product.

Updates

Broadcom Update #1 - Broadcom published an update for their Apache HTTP Server advisory that was originally published on August 1st, 2023.

Broadcom Update #2 - Broadcom published an update for their Apache HTTP Server advisory that was originally published on August 1st, 2023.

Broadcom Update #3 - Broadcom published an update for their sctp_make_strreset_req function advisory that was originally published on August 1st, 2023.

 

For more details on these disclosures, including links to researcher reports, 3rd party advisories, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-e63 - subscription required. [added link to CFSN article, 23:15 EDT, 9-30-23]

 
/* Use this with templates/template-twocol.html */