Showing posts with label TRUMPF. Show all posts
Showing posts with label TRUMPF. Show all posts

Sunday, March 1, 2026

Review – Public ICS Disclosures – Week of 2-21-26 – Part 2

For Part 2 we have seven additional vendor disclosures from Trumpf, VMware (2), Wireshark (3), and Zyxel. There are ten vendor updates from FortiGuard (3), Hitachi Energy, HP (2), Moxa, and Siemens (3). There are 14 researcher reports for products from Owl (11), and Tattile (3). Finally, we have two exploits for products from Supermicro and Tesla.

Advisories

Trumpf Advisory - CERT-VDE published an advisory that discusses a least privilege violation vulnerability in multiple Trumpf products.

VMware Advisory #1 - Broadcom published an advisory that describes four vulnerabilities in the VMware Workstation and Fusion products.

VMware Advisory #2 - Broadcom published an advisory that describes three vulnerabilities in the VMware Aria Operations product.

Wireshark Advisory #1 - Wireshark published an advisory that describes a buffer over-read vulnerability in their RF4CE Profile dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes a NULL pointer dereference vulnerability in their NTS-KE dissector.

Wireshark Advisory #3 - Wireshark published an advisory that describes an allocation of resources without limit or throttling vulnerability in their USB HID dissector.

Zyxel Advisory - Zyxel published an advisory that describes seven vulnerabilities in multiple Zyxel product lines.

Updates

FortiGuard Update #1 - FortiGuard published an update for their FortiOS advisory that was originally published on February 10th, 2026.

FortiGuard Update #2 - FortiGuard published an update for their OpenSSL advisory that was originally published on January 30th, 20276, and most recently updated on February 17th, 2026.

FortiGuard Update #3 - FortiGuard published an update for their cw_acd daemon advisory that was originally published on January 13th, 2026, and most recently updated on January 19th, 2026.

Hitachi Energy Update - Hitachi Energy published an update for their RTU500 advisory that was originally published on April 30th, 2024, and most recently updated on September 9th, 2025.

HP Update #1 - HP published an update for their Intel Xeon Processor advisory that was originally published on October 29th, 2025.

HP Update #2 - HP published an update for their AMD Embedded Processors advisory that was originally published on September 30th, 2025.

Moxa Update #1 - Moxa published an update for their Ethernet Switches advisory that was originally published on January 9th, 2026.

Moxa Update #2 - Moxa published an update for their EDS-P510 Series advisory that was originally published on November 8th, 2025.

Siemens Update #1 - Siemens published an update for their SINEC OS advisory that was originally published on August 12th, 2025, and most recently updated on February 12th, 2026.

Siemens Update #2 - Siemens published an update for their SINEC OS advisory that was originally published on August 12th, 2025, and most recently updated on February 12th, 2026.

Siemens Update #3 - Siemens published an update for their SINEC OS advisory that was originally published on January 28th, 2026.

Researcher Reports

Owl Reports - Nozomi Networks published 11 reports describing vulnerabilities in the Owl OPDS data diode solution.

Tattile Reports - Zero Science published three reports about vulnerabilities in Tattile Cameras.

Exploits

Supermicro Exploit - Indoushka published an exploit for an old (2013) improper restriction of operations within the bounds of a memory buffer vulnerability in the Supermicro Onboard IPMI X9SCL.

Tesla Exploit - Nullze published an exploit for a denial-of-service vulnerability in the Tesla S/3/X.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-5e6 - subscription required.

Sunday, August 31, 2025

Review – Public ICS Disclosures – Week of 8-23-25 – Part 2

For Part 2 we have six additional vendor disclosures from Philips (2), SMA, Trumpf, Welotec, and Wireshark. There are also eight vendor updates from ABB, CODESYS (2), Dell, Hitachi Energy (2), HPE, and Siemens. Finally, we have 11 researcher reports for vulnerabilities in products from Biosig Project (10) and Ilevia.

Advisories

Philips Advisory #1 - Philips published an advisory that discusses an exposure of resources to a wrong sphere vulnerability from Dockers Desktop.

Philips Advisory #2 - Philips published an advisory that discusses an out-of-bounds write vulnerability in Google Chrome.

SMA Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the SMA Sunny Boy 3 product.

Trumpf Advisory - CERT-VDE published an advisory that discusses an exposure of sensitive information to an unauthorized actor vulnerability (with publicly available exploits) in the Trumpf Telepresence Box.

Welotec Advisory – CERT-VDE published an advisory that describes the use of a hard-coded cryptographic key vulnerability in the Welotec egOS WebGUI.

Wireshark Advisory - Wireshark published an advisory that describes an SSH dissector crash vulnerability.

Updates

ABB Update - ABB published an update for their ELSB/BLBA ASPECT advisory that was originally published on August 11th, 2025.

CODESYS Update #1 - CODESYS published an update for their Control V3 advisory that was originally published on August 4th, 2025.

CODESYS Update #2 - CODESYS published an update for their Control V3 NULL pointer dereference advisory that was originally published on August 4th, 2025.

Hitachi Energy Update #1 - Hitachi published an update for their Relion 670/650 advisory that was originally published on June 24th, 2025.

Hitachi Energy Update #2 - Hitachi published an update for their Relion 670/650 reboot vulnerability advisory that was originally published on June 24th, 2025.

HPE Update #1 - HPE published an update for their SAN Switches advisory that was originally published on June 10th, 2025.

HPE Update #2 - HPE published an update for their Compute Scale-up Server 3200 platformsadvisory that was originally published on April 22nd, 2025.

Siemens Update - Siemens published an update for their SIMATIC RTLS advisory that was originally published on August 12th, 2025.

Research Reports

Biosig Reports - Cisco Talos published ten reports describing 16 vulnerabilities (with publicly available exploits) in the Biosig libbiosig library.

Ilevia Report - Zero Science published a report that describes an authentication bypass vulnerability (with a publicly available exploit) in the Ilevia EVE X1/X5 Server.

 

For more information on these disclosures, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-b4c - subscription required.

Sunday, April 27, 2025

Review – Public ICS Disclosures – Week of 4-19-25 – Part 2

For Part 2 we have two additional vendor disclosures from Trumpf, and Zyxel. There are five vendor updates from FortiGuard (2), HPE, Palo Alto Networks, and Rockwell Automation. There are six researcher reports for products from SonicWall and MedDream (5). Finally, we have an exploit for products from OpenSSH.

Advisories

Trumpf Advisory - CERT-VDE published an advisory that discusses an improper restriction of XML external entity reference vulnerability in multiple Trumpf products.

Zyxel Advisory - Zyxel published an advisory that describes two vulnerabilities in their USG FLEX H series firewalls.

Updates

FortiGuard Update #1 - FortiGuard published an update for their RADIUS Protocol advisory that was originally published on August 13th, 2024, and most recently updated on March 14th, 2025.

FortiGuard Update #2 - FortiGuard published an update for their fgfm connection advisory that was originally published on April 8th, 2025, and most recently updated on April 11th, 2025.

HPE Update - HPE published an update for their Cray Data Virtualization Service advisory that was originally published on April 18th, 2025.

Palo Alto Networks Update - Palo Alto Networks published an update for their GlobalProtect App advisory that was originally published on April 9th, 2025, and most recently updated on April 11th, 2025.

Rockwell Update - Rockwell published an update for their ThinManager advisory that was originally published on April 15th, 2025.

Researcher Reports

SonicWall Report - BishopFox published a report on a NULL pointer dereference vulnerability in the SonicWall Sonic OS product.

MedDream Reports - ZDI published five reports describing individual vulnerabilities in the MedDream PACS Server.

Exploits

OpenSSH Exploit - Milad Karimi published an exploit for a race condition vulnerability in the OpenSSH server.

 

For more information on these disclosures, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-d2e - subscription required.

Saturday, August 31, 2024

Review – Public ICS Disclosures – Week of 8-24-24

This week we have 21 vendor advisories from Beckhoff (4), B&R, Dassault Systèmes (4), Elecom (2), Hitachi, Hitachi Energy, HP (2), Meinberg, Panasonic, TRUMPF (2), and Wireshark. There are also eight vendor updates from B&R, Dell, Elecom (5), and Moxa. Finally, we have five exploits for products from Aruba and Elber (4).

Advisories

Beckhoff Advisory #1 - CERT-VDE published an advisory that describes a cross-site scripting vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #2 - CERT-VDE published an advisory that describes an authentication bypass by alternate path or channel vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #3 - CERT-VDE published an advisory that describes a classic buffer overflow vulnerability in the Beckhoff TwinCAT/BSD-based products.

Beckhoff Advisory #4 - CERT-VDE published an advisory that describes an allocation of resources without limit or throttling vulnerability in the Beckhoff TwinCAT/BSD-based products.

B&R Advisory - B&R published an advisory that describes three vulnerabilities in their  APROL condition monitoring software.

Dassault Systèmes  Advisory #1 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their ENOVIA Collaborative Industry Innovator.

Dassault Systèmes  Advisory #2 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DSwym in 3DSwymer.

Dassault Systèmes  Advisory #3 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DDashboard in 3DSwymer.

Dassault Systèmes  Advisory #4 - Dassault Systèmes published an advisory that describes a cross-site scripting vulnerability in their 3DDashboard in 3DSwymer.

Elecom Advisory #1 - JP-CERT published an advisory that describes four vulnerabilities in the Elecom wireless LAN routers and access points.

Elecom Advisory #2 - JP-CERT published an advisory that describes three vulnerabilities in the Elecom wireless LAN routers.

Hitachi Advisory - Hitachi published an advisory that describes an authentication bypass vulnerability in their Ops Center Common Services product.

Hitachi Energy Advisory - Hitachi Energy published an advisory that describes an SQL injection vulnerability in their MicroSCADA X SYS600 product.

HP Advisory #1 - HP published an advisory that discusses two vulnerabilities in their Z4, Z6, and Z8 workstations.

HP Advisory #2 - HP published an advisory that discusses an incorrect default permissions vulnerability in their notebook PC’s.

Meinberg Advisory - Meinberg published an advisory that discusses three vulnerabilities (all with publicly available exploits) in their LANTIME product.

Panasonic Advisory - JP-CERT published an advisory that describes a stack-based buffer overflow vulnerability in the Panasonic Control FPWIN Pro7.

Trumpf Advisory #1 - CERT-VDE published an advisory that discusses the regreSSHion vulnerability.

Trumpf Advisory #2 - CERT-VDE published an advisory that discusses a use after free vulnerability (listed in the CISA Known Exploited Vulnerability Catalog) in the Trumpf TruControl laser control software products.

Wireshark Advisory - Wireshark published an advisory that describes an out-of-bounds read vulnerability in their NTLMSSP dissector.

Updates

B&R Updates - B&R published an update for their Automation Runtime advisory that was originally published on August 9th, 2024.

Dell Update - Dell published an update for their Dell ThinOS advisory that was originally published on June 12th, 2024, and most recently updated on July 19th, 2024.

Elecom Update #1 - JP-CERT published an update for their ELECOM and LOGITEC network devices advisory that was originally published on August 10th, 2024.

Elecom Update #2 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on July 30th, 2024.

Elecom Update #3 - JP-CERT published an update for their wireless LAN routers and wireless LAN repeater advisory that was originally published on March 26th, 2024 and most recently updated on May 28th, 2024.

Elecom Update #4 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on March 26th, 2024 and most recently updated on May 28th, 2024.

Elecom Update #5 - JP-CERT published an update for their wireless LAN routers advisory that was originally published on May 28th, 2024.

Moxa Update - Moxa published an update for their regreSSHion advisory that was originally published on August 2nd, 2024, and most recently updated on August 9th, 2024.

Exploits

Aruba Exploit - Hosein Vita published an exploit for a remote code execution vulnerability in the Aruba 501 CN12G5W0XX wireless access point.

Elber Exploit #1 - LiquidWorm published an exploit for an authentication bypass vulnerability in the Elber ESE DVB-S/S2 Satellite Receiver.

Elber Exploit #2 - LiquidWorm published an exploit for a device configuration vulnerability in the Elber ESE DVB-S/S2 Satellite Receiver.

Elber Exploit #3 - LiquidWorm published an exploit for an authentication bypass vulnerability in the Elber Wayber Analog/Digital Audio.

Elber Exploit #4 - LiquidWorm published an exploit for a device configuration vulnerability in the Elber Wayber Analog/Digital Audio.

 

For more information about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, as well as a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-631 - subscription required.

Sunday, February 4, 2024

Review – Public ICS Disclosures – Week of 1-27-24 – Part 2

For Part 2 we have ten additional vendor disclosures from Schneider, SE-elektronic, Sharp, Sick, Splunk (3), Synology, Trumpf, and Zyxel. We also have five researcher reports for vulnerabilities in products from TELSAT (4) and NAVBLUE. Finally, we have six exploits for products from Electrolink.

Advisory

Schneider Advisory - Schneider published an advisory that discusses the recent cyberattack on their Sustainability Business Division.

SE-elektronic Advisory - Incibe-CERT published an advisory that describes two vulnerabilities in the SE-elektronic E-DDC3.3 automation station.

Sharp Advisory - JP-CERT published an advisory that describes seven vulnerabilities in the Sharp Energy Management Controller with Cloud Services product.

Sick Advisory - Sick published an advisory that discuss a deserialization of untrusted data vulnerability that is listed in CISA’s Known Exploited Vulnerability (KEV) catalog.

Splunk Advisory #1 - Splunk published an advisory that describes an insertion of sensitive information in log files vulnerabilities in their Splunk Add-on Builder product.

Splunk Advisory #2 - Splunk published an advisory that describes an insertion of sensitive information in log files vulnerabilities in the Splunk Add-on Builder product.

Splunk Advisory #3 - Splunk published an advisory that discusses two vulnerabilities in the Splunk Add-on Builder.

Synology Advisory - Synology published an advisory that describes an open redirect vulnerability in their DiskStation Manager (DSM) product.

Trumpf Advisory - CERT-VDE published an advisory that discusses four classic buffer overflow vulnerabilities in the Trumpf Oseon and TruTops Fab products.

Zyxel Advisory - Zyxel published an advisory that describes an OS command injection vulnerability in their NAS products.

Researcher Reports

TELSAT Reports - Zero Science published four reports about individual vulnerabilities in the TELSAT marKoni FM Transmitter.

NAVBLUE Report - Pentest Partners published a report describing the lack of an active application transport security (ATS) control in the NAVBLUE Flysmart+ Manager electronic flight bag.

Exploits

Electrolink Exploit #1 - Liquid Worm published an exploit for a credential exposure vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #2 - Liquid Worm published an exploit for a credential exposure vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #3 - Liquid Worm published an exploit for an authentication bypass vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #4 - Liquid Worm published an exploit for a remote authentication vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #5 - Liquid Worm published an exploit for a remote denial-of-service vulnerability in the Electrolink FM/DAB/TV Transmitter.

Electrolink Exploit #6 - Liquid Worm published an exploit for a MPFS image remote code execution vulnerability in the Electrolink FM/DAB/TV Transmitter.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-560 - subscription required.

Saturday, September 16, 2023

Review – Public ICS Disclosures – Week of 9-9-23 – Part 1

For the week of Cyber Tuesday, the number of disclosures is very reasonable. Still, I am doing a two-part post. For Part 1 we have 16 vendor disclosures for DrayTek, FortiGuard, HP, HPE (2), Insyde (2), JTEKT, Palo Alto Networks (2), QNAP (3), Rockwell Automation (2), and Trumpf. There is one vendor update from Broadcom.

For Part 2 I will be looking at advisories and updates from Schneider and Siemens as well as four exploits.

Advisories

DrayTek Advisory - DrayTek published an advisory that describes a format string vulnerability in their Vigor routers.

FortiGuard Advisory - FortiGuard published an advisory that describes a cross-site scripting vulnerability in their FortiProxy and FortiOS products.

HP Advisory - HP published an advisory that discusses two vulnerabilities in multiple products.

HPE Advisory #1 - HPE published an advisory that describes two authentication bypass vulnerabilities in their OneView infrastructure management software.

HPE Advisory #2 - HPE published an advisory that discusses the Downfall Attacks vulnerability.

Insyde Advisory #1 - Insyde published an advisory that discusses four vulnerabilities in their InsydeH2O product.

Insyde Advisory #2 - Insyde published an advisory that describes an arbitrary code execution vulnerability in their SystemFirmwareManagementRuntimeDxe.

JTEKT Advisory - JTEKT published an advisory that describes two vulnerabilities in their Kostac PLC Programming Software.

Palo Alto Networks Advisory #1 - Palo Alto Networks published an advisory that describes an improper handling of exceptional conditions vulnerability in their Cortex XDR Agent.

Palo Alto Networks Advisory #2 - Palo Alto Networks published an advisory that discusses an improper validation of integrity check value vulnerability in their PAN-OS and Prisma products.

QNAP Advisory #1 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #2 - QNAP published an advisory that describes two NULL pointer dereference vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes two out-of-bounds write vulnerabilities in their QTS, QuTS hero and QuTScloud products.

Rockwell Advisory #1 - Rockwell published an advisory that describes an improper input validation vulnerability in their FactoryTalk View Machine Edition product.

Rockwell Advisory #2 - Rockwell published an advisory that discusses four vulnerabilities in their KEPServerEX product.

Trumpf Advisory - CERT-VDE published an advisory that discusses two vulnerabilities in the TRUMPF License Expert.

Updates

Broadcom Update - Broadcom published an update for their use-after-free advisory that was originally published on August 1st, 2023.

 

For more details about these disclosures, including links to researcher reports, 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-900 - subscription required.

Saturday, October 22, 2022

Review – Public ICS Disclosures – Week of 10-15-22

This week we have fourteen vendor disclosures from Bosch (2), Broadcom, GE Grid Solutions, HP, Meinberg, Milestone, Siemens, SonicWall, Tanzu, TRUMPF, WAGO (2), and Yokogawa Test and Measurement. We also have a vendor update from HPE. Finally, we have an exploit for products from Tanzu.

Bosch Advisory #1 - Bosch published an advisory that discusses an improper validation of integrity check value vulnerability in their Bosch DSA E2800 products.

Bosch Advisory #2 - Bosch published an advisory that describes two cross-site scripting vulnerabilities in their VIDEOJET multi 4000.

Broadcom Advisory - Broadcom published an advisory that discusses the Text4Shell vulnerability.

GE Grid Solutions Advisory - GE Grid Solutions published an advisory that describes vulnerabilities in their MS 3000 Transformers monitoring system.

HP Advisory - HP published an advisory that discusses a PCR measurement vulnerability in multiple HP products.

Meinberg Advisory - Meinberg published an advisory that discusses two vulnerabilities (both with publicly available exploits) in their LANTIME firmware.

Milestone Advisory - Milestone published an advisory that discusses an authentication bypass vulnerability in their Mobile Server.

Siemens Advisory - Siemens published an advisory that describes an authentication bypass vulnerability in their Siveillance Video Mobile Server.

SonicWall Advisory - SonicWall published an advisory that discusses the Text4Shell vulnerability.

Tanzu Advisory #1 - Tanzu published an advisory that describes an HTTP request forgery vulnerability in their Spring Data REST.

Tanzu Advisory #2 - Tanzu published an advisory that describes an information disclosure vulnerability in their Reactor Netty HTTP Server.

TRUMPF Advisory - CERT-VDE published an advisory that describes an improper access control vulnerability in multiple TRUMPF products.

WAGO Advisory #1 - CERT-VDE published an advisory that discusses fourteen vulnerabilities in the WAGO 750 series controllers and WAGO-I/O-PRO.

WAGO Advisory #2 - CERT-VDE published an advisory that describes an expected behavior violation vulnerability in multiple WAGO products.

Yokogawa Advisory - Yokogawa Test and Measurement published an advisory that describes a buffer overflow vulnerability in their WTViewerE.

HPE Update - HPE published an update for their ProLiant Servers advisory that was originally published on May 18th, 2022.

Tanzu Exploit - Ayan Saha published a Metasploit module for a code injection vulnerability in the Tanzu Spring Cloud Gateway.

 

For more details on these disclosures, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-1b0 - subscription required.


Saturday, May 7, 2022

Review – Public ICS Disclosures – Week of 4-30-22 – Part 1

Another busy week requiring a two part post. In Part 1 this week we have 19 vendor disclosures from Aruba Networks (3), Aveva, Axis, Belden (3), Bosch, Broadcom (8), Emerson, and TRUMPF.

Aruba Advisory #1 - Aruba published an advisory discussing an infinite loop vulnerability in multiple products. This is a third-party (OpenSSL) vulnerability.

Aruba Advisory #2 - Aruba published an advisory describing 21 vulnerabilities in their ClearPass Policy Manager.

Aruba Advisory #3 - Aruba published an advisory discussing the TLStorm 2.0 vulnerabilities.

Aveva Advisory - Aveva published an advisory describing an exposure of resource to wrong sphere vulnerability in their  InTouch Access Anywhere and Plant SCADA Access Anywhere products.

Axis Advisory - Axis published an advisory discussing two vulnerabilities (with one known exploit available) in their AXIS P7701 Video Decoder.

Belden Advisory #1 - Belden published an advisory discussing eight vulnerabilities (two with known exploits) in their Provize Basic Frontend.

Belden Advisory #2 - Belden published an advisory discussing two vulnerabilities (one with known exploit) in their Provize Basic Backend.

Belden Advisory #3 - Belden published an advisory discussing an uncontrolled resource consumption vulnerability (with a known exploit) in their Provize Basic product.

Bosch Advisory - Bosch published an advisory discussing five vulnerabilities in their PLC applications of the control systems ctrlX CORE, IndraLogic, IndraMotion MTX, IndraMotion MLC and IndraMotion MLD systems.

Broadcom Advisory #1 - Broadcom published an advisory discussing a link following vulnerability in their Brocade SANnav product.

Broadcom Advisory #2 - Broadcom published an advisory discussing an improper input validation vulnerability (with a known exploit) in their Brocade SANnav product.

Broadcom Advisory #3 - Broadcom published an advisory discussing a deserialization of untrusted data vulnerability in their Brocade SANnav product.

Broadcom Advisory #4 - Broadcom published an advisory describing an information exposure vulnerability in their Brocade SANnav product.

Broadcom Advisory #5 - Broadcom published an advisory describing a plain-text storage of sensitive information vulnerability in their Brocade SANnav product.

Broadcom Advisory #6 - Broadcom published an advisory describing a SQL injection vulnerability in their Brocade SANnav product.

Broadcom Advisory #7 - Broadcom published an advisory describing an inadequate password encryption vulnerability in their Brocade SANnav product.

Broadcom Advisory #8 - Broadcom published an advisory describing a role-based access control vulnerability in their Brocade SANnav product.

Emerson Advisory - Emerson published an advisory discussing two vulnerabilities in their AVENTICS AF2 Series flow sensors.

TRUMPH Advisory - CERT-VDE published an advisory describing a missing authentication for critical function vulnerability in the TRUMPF TruTops products.

 

For more details on these advisories, including links to third-party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-c2b - subscription required.

 

Saturday, March 27, 2021

Public ICS Disclosures – Week of 3-20-21

This week we have 27 vendor disclosures from BD (3), Bosch, TRUMPF, GE Grid Systems (19), Mitsubishi Electric, Moxa, and Rockwell Automation. We have a researcher report for products from Ovarro. Finally, there were two exploits published for products from VMWare and Advantech.

BD Advisories

BD published patch advisories for the below listed products. These are the 3rd party patches that have been tested by BD on the listed products.

BD Care Coordination Engine (CCE),

Security Patches: BD Pyxis™ Products, and

Security Patches: BD Alaris™ Systems Manager

Bosch Advisories

Bosch published an advisory describing seven uncontrolled search path element vulnerabilities in multiple Bosch products. The vulnerabilities were reported by Nir Yehoshua, Dhiraj Mishra, and Eli Paz of CyberArk. Bosch has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

TRUMPF Advisory

CERT-VDE published an advisory describing an out-of-bounds write vulnerability in the TRUMPF TruControl laser control software. The vulnerability was reported by Qualys Research Labs. TRUMPF has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

GE Grid Advisories

GE published advisories for the below listed products. These may be updates for previously issued advisories, but only GE customers can access the advisories, so I do not know for sure:

C30 Controller

C60 Breaker Management Relay

C70 Capacitor Bank Protection and Control System

B30 Bus Differential Relay

B90 Bus Differential System

F35 Multiple Feeder Management Relay

F60 Feeder Management Relay

G30 Generator Management Relay

G60 Generator Management Relay

L30 Line Current Differential Relay

L60 Line Phase Comparison Relay

L90 Line Current Differential Relay

M60 Motor Management Relay

D30 Line Distance Relay

D60 Line Distance Relay

N60 Network Stability and Synchrophasor Measurement System

T35 Transformer Management Relay

T60 Transformer Management Relay

UR Family of Protection Relays

Mitsubishi Advisory

Mitsubishi published an advisory discussing a heap-based buffer overflow vulnerability in a third-party TCP/IP stack (Treck). Mitsubishi is providing generic workarounds to mitigate the vulnerability.

NOTE: Mitsubishi is only reporting one of the four TCP/IP stack vulnerabilities reported by Treck.

Moxa Advisory

Moxa published an advisory describing ten vulnerabilities in their EDR-810 Series Security Routers. The vulnerabilities were reported by the Russian BDU FSTEC. Moxa has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The ten reported vulnerabilities are:

• Improper Input Validation - CVE-2014-2284 (Linux ICMP-MIB implementation),

• Resource Management Errors - CVE-2015-1788 (Open SSL),

Improper Restriction of Operations within the Bounds of a Memory Buffer - CVE-2016-10012 (Open SSH),

Exposure of Sensitive Information to an Unauthorized Actor - CVE-2015-3195 (Open SSL),

Improper Input Validation - CVE-2016-6515 (open SSH, Exploit),

Improper Input Validation - CVE-2017-17562 (EmbedThis, Exploit),

Cryptographic Issues - CVE-2013-0169 (TLS Protocol),

• Permissions, Privileges, and Access Controls - CVE-2013-1813 (BusyBox, Exploit), and

• Numeric Errors - CVE-2010-2156 (ISC DHP, Exploit)

Rockwell Advisory

Rockwell published an advisory discussing eight vulnerabilities in their Stratix Switches. These are third-party (Cisco) vulnerabilities. Rockwell has new versions that mitigate the vulnerability.

The eight reported vulnerabilities are:

• Privilege escalation (2) - CVE-2021-1392 and CVE-2021-1442,

• Cross-site web socket hijacking - CVE-2021-1403,

• Denial of service (3) - CVE-2021-1352, CVE-2021-1220, and CVE-2021- 1356, and

• Command injection (2) - CVE-2021-1452 and CVE-2021-1443,

NOTE: Links above are to the Cisco advisories.l

Ovarro Report

Claroty published a report describing the five vulnerabilities that were reported earlier this week in the Ovarro TBox RTUs.

VMWare Exploit

WVU published a Metasploit module for a remote code execution vulnerability in the VMware View Planner. This vulnerability was previously reported by VMware.

Advantech Exploit

Spencer McIntyre published a Metasploit module for a missing authentication for critical function vulnerability in the Advantech iView. This vulnerability was previously reported by Advantech.

 
/* Use this with templates/template-twocol.html */