Showing posts with label Talos. Show all posts
Showing posts with label Talos. Show all posts

Sunday, August 13, 2023

Review – Public ICS Disclosures – Week of 8-5-23 – Part 2

For Part 2 we have a vendor disclosure for products from Schneider. There are also 17 vendor updates from B&R, FortiGuard, Schneider (3) and Siemens (12). Finally, we have 20 researcher reports for products from Advantech, BlueMark, NVIDIA, Softing (11), and Inductive Automation (6).

Advisories

Schneider Advisory - Schneider published an advisory that describes an improper restriction of operations within the bounds of a memory buffer in their Pro-face GP-Pro EX product.

Updates

B&R Update - B&R published an update for their SLP based traffic advisory that was originally published on May 31st, 2023.

FortiGuard Update - FortiGuard published an update for their FortiOS buffer overflow advisory that was originally published on July 28th, 2023.

Schneider Update #1 - Schneider published an update for their EcoStruxure Control Expert advisory that was originally published on January 10th, 2023, and most recently updated on March 14th, 2023.

Schneider Update #2 - Schneider published an update for their EcoStruxure Control Expert advisory that  was originally published on January 10th, 2023, and most recently updated on July 11th, 2023.

Schneider Update #3 - Schneider published an update for their CODESYS Runtime advisory that was originally published on July 11th, 2023.

Siemens Update #1 - Siemens published an update for their Multiple File Parsing advisory that was originally published on May 9th, 2023.

Siemens Update #2 - Siemens published an update for their Authentication Bypass advisory that was originally published on March 14th, 2023 and most recently updated on June 13th, 2023.

Siemens Update #3 - Siemens published an update for their Linux Kernel advisory that was originally published on June 13th, 2023 and most recently updated on July 11th, 2023.

Siemens Update #4 - Siemens published an update for their File Parsing Vulnerabilities advisory that was originally published on July 11th, 2023.

Siemens Update #5 - Siemens published an update for their OPC Foundation advisory that was originally published on April 11th, 2023 and most recently updated on June 13th, 2023.

Siemens Update #6 - Siemens published an update for their IPU 2022.3 Vulnerabilities advisory that was originally published on February 14th, 2023 and most recently updated on July 11th, 2023.

Siemens Update #7 - Siemens published an update for their Missing CSRF Protection advisory that was originally published on November 8th, 2022, and most recently updated on July 11th, 2023.

Siemens Update #8 - Siemens published an update for their additional GNU/Linux subsystem advisory that was originally published on November 27th, 2018 and most recently updated on July 11th, 2023.

Siemens Update #9 - Siemens published an update for their Insyde BIOS Vulnerabilities advisory that was originally published on May 22nd, 2022 and most recently updated on July 11th, 2023.

Siemens Update #10 - Siemens published an update for their SISCO Stack Vulnerability advisory that was originally published on December 13th, 2022 and most recently updated on March 14th, 2023.

Siemens Update #11 - Siemens published an update for their Privilege Management Vulnerability advisory that was originally published on December 13th, 2022. 

Researcher Reports

Advantech Report - CyberDanube published a report that describes two cross-site scripting vulnerabilities in the Advantech EKI-1524-CE series, EKI-1522 series, EKI-1521 series products.

BlueMark Reports - Nozomi Networks published three reports about individual vulnerabilities in the BlueMark DroneScout ds230 Remote ID receiver.

NVIDIA Reports - Cisco TALOS published three reports for individual vulnerabilities in the NVIDIA GPU Display Driver.

Softing Report #1 - ZDI published a report that describes a resource exhaustion vulnerability in the Softing edgeConnector product.

Softing Report #2 - ZDI published a report that describes a directory traversal vulnerability in the Softing Integration Server.

Softing Reports #3-5 - ZDI published three reports of individual vulnerabilities in the Softing edgeAggregator.

Softing Reports #6-9 - ZDI published four reports of individual vulnerabilities in the Softing Secure Integration Server.

Softing Report #10 - ZDI published a report of a NULL pointer dereference vulnerability in the Softing edgeConnector.

Softing Report #11 - ZDI published a report of a hard-coded cryptographic key vulnerability in the Softing Secure Integration Server.

Inductive Automation Reports - ZDI published six reports of vulnerabilities in the Inductive Automation Ignition product.

 

For more details on these disclosures, including a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-1b8 - subscription required.

Saturday, July 8, 2023

Review – Public ICS Disclosures – Week of 7-1-23

This week we have eleven vendor disclosures from Aruba Networks, Bosch (2), Enphase, Frauscher Sensortechnik, Hikvision, Moxa, Softing (2), VMware and Zyxel. And we have 29 researcher reports for products from Panasonic (3), Milesight (25), and Siemens.

Advisories

Aruba Advisory - Aruba published an advisory that describes nine vulnerabilities in the Aruba OS products.

Bosch Advisory #1 - Bosch published an advisory that discusses two vulnerabilities in their FL MGUARD family devices.

Bosch Advisory #2 - Bosch published an advisory that discusses a missing authentication for critical function vulnerability in their SLC-0-GPNT00300 interface module.

Enphase Advisory - Enphase published an advisory that describes an OS command injection vulnerability in their Enphase IQ Gateway (Envoy).

Frauscher Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1.

Hikvision Advisory - Hikvision published an advisory that describes two vulnerabilities in their access control/intercom products.

Moxa Advisory - Moxa published an advisory that describes an observable response discrepancy vulnerability in their TN-5900 Series product.

Softing Advisory #1 - Softing published an advisory that describes two vulnerabilities in their OPC UA C++ SDK and Secure Integration Server.

Softing Advisory #2 - Softing published an advisory that describes an uncontrolled resource consumption vulnerability in a number of their products.

VMware Advisory - VMware published an advisory that describes an authentication bypass vulnerability in their SD-WAN (Edge) product.

Zyxel Advisory - Zyxel published an advisory that describes a classic buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Researcher Reports

Panasonic Reports - AWESEC published three reports describing individual vulnerabilities in the Panasonic Panasonic AiSEG2.

Milesight Reports - Talos Intelligence published 25 reports (some with multiple vulnerabilities) for the Milesight UR32L urvpn_client and MilesightVPN server.

Siemens Report - SEC Consult published a report describing the four vulnerabilities in the Siemens A8000 product.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-bcb - subscription required.

Saturday, June 3, 2023

Review – Public ICS Disclosure – Week of 5-27-23

This week we have 31 vendor disclosures from BD, Bosch, B&R, Contec, Eaton, Fuji Electric, Hitachi Energy (2), HPE (3), Mitsubishi, Splunk (15), VMware, and Zyxel (3). There are also four vendor updates from HPE (2) and Moxa (2). We also have 40 researcher reports for vulnerabilities for products from Delta Electronics (22), Fatek Automation (11), Mitsubishi, and Unified Automation (6). Finally, we have an exploit for products from Seagate.

Advisories

BD Advisory - BD published an advisory that discusses a buffer underflow vulnerability in some of their Kiestra products.

Bosch Advisory - Bosch published an advisory that describes a chip damaging vulnerability in their CPP13 and CPP14 cameras.

B&R Advisory - B&R published an advisory that discusses an abuse of service location protocol vulnerability in their ARPOL product.

Contec Advisory - Contec published an advisory that describes seven vulnerabilities in their CONPROSYS HMI System.

Eaton Advisory - Eaton published an advisory that describes a group access authorization logic vulnerability in their SecureConnect portal.

Fuji Electric - JP CERT published an advisory that describes three vulnerabilities in the Fuji Electric FRENIC RHC Loader.

Hitachi Energy Advisory #1 - Hitachi published an advisory that describes an improper output neutralization for logs vulnerability in their UNEM product.

Hitachi Energy Advisory #2 - Hitachi published an advisory that that describes an improper output neutralization for logs vulnerability in their FOXMAN-UN product.

HPE Advisory #1 - HPE published an advisory that describes an arbitrary code execution vulnerability in their Smart Storage Administrator (SSA) Offline product.

HPE Advisory #2 - HPE published an advisory that discusses four vulnerabilities in their HP-UX BIND product.

HPE Advisory #3 - HPE published an advisory that describes a denial of service vulnerability in their HP-UX IPv6 Stack.

Mitsubishi Advisory - Mitsubishi published an advisory that describes four vulnerabilities in their MELSEC iQ-R Series/iQ-F Series EtherNet/IP modules and EtherNet/IP configuration tools.

Splunk Advisories 1-3 - Splunk published three advisories for product updates for third party vulnerabilities.

Splunk Advisories 4-15 - Splunk published 12 advisories for individual vulnerabilities in multiple products.

VMware Advisory - VMware published an advisory that describes an insecure redirect vulnerability in their Workspace ONE Access and Identity Manager products.

Zyxel Advisory #1 - Zyxel published an advisory that describes two classic buffer overflow vulnerabilities in their firewalls.

Zyxel Adviosry #2 - Zyxel published an advisory that describes an OS command injection vulnerability in some of their NAS versions.

Zyxel Advisory #3 - Zyxel published an advisory that discusses recent attacks on their ZyWALL devices.

Updates

HPE Update #1 - HPE published an update for their StoreEasy Servers advisory that was originally published on February 14th, 2023 and most recently updated on March 23rd, 2023.

HPE Update #2 - HPE published an update for their OneView advisory that was originally published on February 6th, 2023.

Moxa Update #1 - Moxa published an update for their MXsecurity advisory that was originally published on March 8th, 2023 and most recently updated on May 23rd, 2023.

Moxa Update #2 - Moxa published an update for their Arm-based Computer advisory that was originally published on November 22nd, 2022.

Researcher Reports

Delta Electronics Reports - ZDI published 22 reports about individual vulnerabilities in the Delta CNCSoft-B product.

Fatek Reports - ZDI published eleven reports about individual vulnerabilities in the Fatek FvDesigner.

Mitsubishi Report - Talos Intelligence published a report describing a memory corruption vulnerability in the Mitsubishi MELSEC iQ-F FX5U MELSOFT.

Unified Automation Report #1 - Claroty published a report that describes an object validation vulnerability in the Unified Automation UaGateway.

Unified Automation Reports #2-6 - ZDI published five reports describing vulnerabilities in the Unified Automation UaGateway.

Exploits

Seagate Exploit - Ege Balci published an metsploit module for an OS command injection vulnerability in the Seagate Central External NAS Storage device.


For more details about these disclosures, including links to researcher reports and exploits, as well as a brief description of new information in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-5-27 - subscription required.


Sunday, May 14, 2023

Review – Public ICS Disclosures – Week of 5-6-23 – Part 2

For Part 2 this week we have four additional vendor disclosures from Schneider. We also have 18 updates for products from Schneider (2) and Siemens (16). There are three researcher reports for products from Advantech and Weston (2).

Advisories

Schneider Advisory #1 - Schneider published an advisory that describes an improper XML external entity reference vulnerability in their OPC Factory Server.

Schneider Advisory #2 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power Operation, EcoStruxure Power SCADA Operation products.

Schneider Advisory #3 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power Operation, EcoStruxure Power SCADA Operation products.

Schneider Advisory #4 - Schneider published an advisory that discusses an improper authorization vulnerability in their EcoStruxure Power SCADA Anywhere products.

Updates

Schneider Update #1 - Schneider published an update for their INFRA:HALT advisory that was originally published on February 8th, 2022, and most recently updated on February 14th, 2023.

Schneider Update #2 - Schneider published an update for their BadAlloc advisory that was originally published on April 12th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #1 - Siemens published an update for their SIPROTEC 5 devices advisory that was originally published on April 11th, 2023.

Siemens Update #2 - Siemens published an update for their Siemens Industrial Products using Intel CPUs advisory that was originally published on August 10th, 2021 and most recently updated on December 13th, 2022.

Siemens Update #3 - Siemens published an update for their TIA Portal advisory that was originally published on April 11th, 2023.

Siemens Update #4 - Siemens published an update for their SIMATIC S7-400 CPUs advisory that was originally published on November 13th, 2018 and most recently updated on January 10th, 2023.

Siemens Update #5 - Siemens published an update for their OpenSSL Affecting Industrial Products advisory that was originally published on June 14th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #6 - Siemens published an update for their Siemens Industrial Products using Intel CPUs advisory that was originally published on February 14th, 2023.

Siemens Update #7 - Siemens published an update for their TIA Project-Server advisory that was originally published on February 14th, 2023.

Siemens Update #8 - Siemens published an update for their Polarion ALM advisory that was originally published on April 11th, 2014.

Siemens Update #9 - Siemens published an update for their Industrial Products advisory that was originally published on March 20th, 2018 and most recently updated on April 11th, 2023.

Siemens Update #10 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 11th, 2023.

Siemens Update #11 - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022.

Siemens Update #12 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 9th, 2019.

Siemens Update #13 - Siemens published an update for their e Web Server Login Page of Industrial Controllers advisory that was originally published on November 8th, 2022 and most recently updated on April 11th, 2023.

Siemens Update #14 - Siemens published an update for their Profinet Devices advisory that was originally published on October 8th, 2018, and most recently update on January 10th, 2023.

Siemens Update #15 - Siemens published an update for their Industrial Products advisory that was originally published on December 13th, 2022, and most recently updated on April 11th, 2023.

Siemens Update #16 - Siemens published an update for their n Industrial Real-Time (IRT) Devices advisory that was originally published on October 8th, 2019, and most recently updated on April 11th, 2023.

Researcher Reports

Advantech Report - Cyber Danube published a report about three vulnerabilities in the Advantech EKI-1524-CE series, EKI-1522 series, EKI-1521 series serial device servers.

Weston Reports - Cisco Talos published two reports about three vulnerabilities in the Weston Embedded uC-FTPs.

 

For more details on these disclosures, including a brief summary of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-e8f - subscription required.

Saturday, January 28, 2023

Review – Public ICS Disclosures – Week of 1-21-23

This week we have an OpenSSL 3.0 advisory from Dell. We have seven vendor disclosures from Carrier, Contec, GE Grid Solutions, Meinberg, Omron, and PulseSecure (2). We also have three vendor updates from CODESYS, HPE, and PcVue. Finally, we have 16 researcher reports for products from Siretta (14), Zyxel, and Delta Electronics.

Open SSL 3.0 Advisories

Dell published an advisory that discusses the OpenSSL 3.0 vulnerabilities.

Vendor Advisories

Carrier Advisory - Carrier published an advisory that discusses multiple authentication bypass vulnerabilities in their WebCTRL® and i-Vu® software.

Contec Advisory - Contec published an advisory that describes an SQL injection vulnerability in the Contec CONPROSYS HMI System.

GE Grid Solutions Advisory - GE Grid Solutions published an advisory for their DS Agile Distributed Control System.

Meinberg Advisory - Meinberg published an advisory that discusses eight vulnerabilities in their LANTIME product.

Omron Advisory - JP Cert published an advisory that describes an improper restriction of an XML entity reference vulnerability in the OMRON CX-Motion Pr.

PulseSecure Advisory #1 - PulseSecure published an advisory that discusses a use-after-free vulnerability.

PulseSecure Advisory #2 - PulseSecure published an advisory that discusses a double free vulnerability.

Vendor Updates

CODESYS Update - CODESYS published an update for their Control V3 communication server advisory that was originally published on November 22nd, 2022 and most recently updated on December 14th, 2022.

HPE Update - HPE published an update for their IceWall advisory that was originally published on March 9th, 2018 and most recently updated on May 26th, 2021.

PcVue Update - PcVue published an update for their email and SMS accounts advisory that was originally published on November 25th, 2022 and most recently updated on December 20th, 2022.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-22-354-03) to reflect this information.

Researcher Reports

Siretta Report #1 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing 46 stack-based buffer overflow vulnerabilities.

Siretta Report #2 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a directory traversal vulnerability.

Siretta Report #3 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing four command injection vulnerabilities.

Siretta Report #4 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a heap-based buffer overflow vulnerability.

Siretta Report #5 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a file write vulnerability.

Siretta Report #6 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a leftover debug code vulnerability.

Siretta Report #7 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #8 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #9 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #10 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a stack-based buffer overflow vulnerability.

Siretta Report #11 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a directory traversal vulnerability.

Siretta Report #12 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing an OS command injection vulnerability.

Siretta Report #13 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a directory traversal vulnerability.

Siretta Report #14 - Talos published a report for the Siretta QUARTZ-GOLD industrial router describing a stack-based buffer overflow vulnerability.

Zyxel Report - Positive Technologies published a report describing an improper check for unusual or exceptional conditions vulnerability in Zyxel switches.

Delta Report - Tenable published a report describing a privilege escalation vulnerability in the Delta Electronics InfraSuite Device Master.

 

For more details about these disclosures, including links to third-party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-e09 - subscription required.

Saturday, January 21, 2023

Review – Public ICS Disclosures – Week of 1-14-23

This week we have twelve vendor disclosures from Campbell Scientific, Contec, HIMA, HP, Medtronic, and Wireshark (7). We also have two researcher disclosures for products from Mitsubishi and GE,

Vendor Disclosures

Campbell Advisory - INCIBE-CERT published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in the Campbell dataloggers.

Contec Advisory - Contec published an advisory that describes SQL injection vulnerabilities in their CONPROSYS HMI System.

HIMA Advisory - CERT-VDE published an advisory that describes an unquoted Windows search path vulnerability in multiple HIMA X-OPC and X-OTS products.

HP Advisory - HP published an advisory that discusses eight vulnerabilities in multiple HP products.

Medtronic Advisory - Medtronic published an end-of-life notice for their superDimension™ navigation system.

Wireshark Advisory #1 - Wireshark published an advisory that describes a packet injection vulnerability in their EAP dissector.

Wireshark Advisory #2 - Wireshark published an advisory that describes a memory leak vulnerability in their NFS dissector.

Wireshark Advisory #3 - Wireshark published an advisory that describes a denial of service vulnerability in their Dissection engine.

Wireshark Advisory #4 - Wireshark published an advisory that describes a denial of service vulnerability in their GNW dissector.

Wireshark Advisory #5 - Wireshark published an advisory that describes a denial of service vulnerability in their iSCSI dissector.

Wireshark Advisory #6 - Wireshark published an advisory that describes an excessive loop vulnerability in multiple dissectors.

Wireshark Advisory #7 - Wireshark published an advisory that describes a denial of service vulnerability in their TIPC dissector.

Researcher Reports

Mitsubishi Report - CISCO Talos published a report that describes an authentication bypass vulnerability in the Mitsubishi MELSEC iQ-FX5U webserver.

GE Report - Claroty published a report that describes five vulnerabilities in the GE Proficy Historian. The report contains proof-of-concept code.

 

For more details about these disclosures, including links to third-party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-6c3 - subscription required.

Sunday, October 16, 2022

Review – Public ICS Disclosures – Week of 10-8-22 – Part 2

For Part 2 this week we have five additional vendor disclosures from Schneider (4), and WAGO. We also have sixteen updates from Fanuc, HPE, Omron (2), Schneider (8), and Siemens (4). We have nine researcher reports for products from CCCERT (2), Robustel (6), and VMware.

Schneider Advisory #1 - Schneider published an advisory that describes six vulnerabilities in their EcoStruxure™ Operator Terminal Expert and Pro-face BLUE products.

Schneider Advisory #2 - Schneider published an advisory that discusses two vulnerabilities (one with known exploit) in their EcoStruxure Panel Server Box (PAS900).

Schneider Advisory #3 - Schneider published an advisory that discusses two vulnerabilities in their SAGE RTU products.

Schneider Advisory #4 - Schneider published an advisory that describes an improper input validation vulnerability in their s EcoStruxure™ Power Operation and Power SCADA Operation software.

WAGO Advisory - CERT-VDE published an advisory that describes an uncontrolled resource consumption vulnerability in the FTP server in WAGO 750 series controllers.

Fanuc Update - Fanuc published an update for their ROBOGUIDE advisory that was originally published on April 8th, 2022 and most recently updated on June 29th, 2022.

HPE Update - HPE published an update for their Integrated Lights-Out 5 that was originally published on September 15th, 2022.

Omron Update #1 - Omron published an update for their NJ/NXseries Machine Automation Controllers advisory that was originally published on July 1st, 2022.

Omron Update #2 - Omron published an update for their NJ/NXseries Machine Automation Controllers advisory that was originally published on July 1st, 2022.

Schneider Update #1 - Schneider published an update for their Log4Shell advisory.

Schneider Update #2 - Schneider published an update for their Modicon PAC Controllers advisory that was originally published on August 9th, 2022 and most recently updated on September 6th, 2022.

Schneider Update #3 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on August 9th, 2022 and most recently updated on September 6th, 2022.

Schneider Update #4 - Schneider published an update for their EcoStruxureTM Control Expert advisory that was originally published on July 13th, 2021 and most recently updated on September 6th, 2022.

Schneider Update #5 - Schneider published an update for their Modicon PAC Controllers advisory that was originally published on August 10th, 2021 and most recently updated on September 6th, 2022.

Schneider Update #6 - Schneider published an update for their BadAlloc advisory that was originally published on November 9th, 2021 and most recently updated on September 13th, 2022.

Schneider Update #7 - Schneider published an update for their Modicon Controllers advisory that was originally published on September 26th, 2019 and most recently updated on September 6th, 2022.

Schneider Update #8 - Schneider published an update for their Embedded FTP Servers advisory that was originally published on March 22nd, 2018 and most recently updated on September 13th, 2022.

Siemens Update #1 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published in 2018 and most recently updated on September 13th, 2022.

Siemens Update #2 - Siemens published an update for their Insyde BIOS advisory that was originally published on February 22nd, 2022 and most recently updated on August 9th, 2022.

Siemens Update #3 - Siemens published an update for their SpringShell advisory that was originally published on April 19th, 2022 and most recently updated on June 14th, 2022.

Siemens Update #4 - Siemens published an update for their OpenSSL advisory that was originally reported on July 13th, 2021 and most recently updated on August 9th, 2022.

CCCERT Report #1 - BDU published a report of an open redirect vulnerability in the CCCERT VINCE program.

CCCERT Report #2 - BDU published a report of an open redirect vulnerability in the CCCERT VINCE program.

NOTE: The CCCERT VINCE program is the vulnerability reporting program run by CCCERT and used by NCCIC-ICS.

Robustel Report #1 - TALOS published a report discussing a command injection vulnerability in the Robustel R1510 Lite Industrial IoT Gateway.

Robustel Report #2 - TALOS published a report describing eleven denial of service vulnerabilities in the Robustel R1510.

Robustel Report #3 - TALOS published a report describing a firmware update vulnerability in the Robustel R1510. The report contains proof-of-concept code.

Robustel Report #4 - TALOS published a report describing a directory traversal vulnerability in the Robustel R1510. The report contains proof-of-concept code.

Robustel Report #5 - TALOS published a report discussing an OS command injection vulnerability in the Robustel R1510.

Robustel Report #6 - TALOS published a report discussing an OS command injection vulnerability in the Robustel R1510. The report contains proof-of-concept code.

VMware Report - TALOS published a report describing a deserialization of untrusted data vulnerability in the VMware vCenter Server Platform Services.

 

For more details on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-8b0 - subscription required.


Sunday, July 31, 2022

Review – Public ICS Disclosure – Week of 7-23-22 – Part 2

For Part 2 this week we have three additional vendor disclosures from FileWave, OPCLabs, and Unified Automation. We also have nine vendor updates from CODESYS, HP, Mitsubishi (3), VMware, and Yokogawa (3). We also have four researcher reports for products from DD-WRT, Asuswrt, FreshTomato, and Nuki. Finally, we have two exploits for products from Dingtian, and Roxy-WI.

FileWave Advisory - FileWave published a blog post that describes two vulnerabilities in their FileWave Management Suite.

OPC Labs Advisory - OPC Labs published an advisory that describes a deserialization of untrusted data vulnerability in their QuickOPC Connectivity Explorer.

Unified Automation Advisory - Incibe CERT published an advisory that describes two vulnerabilities in the Unified Automation's OPC UA C++ Demo Server.

CODESYS Update - CODESYS published an update for their Development System V3 advisory that was originally published on July 15th, 2021 and most recently updated on June 3rd, 2022.

HP Update - HP published an update for their NVIDIA GPU Display Driver advisory that was originally published on June 2nd, 2022 and most recently updated on June 23rd, 2022.

Mitsubishi Update #1 - Mitsubishi published an update for their Multiple FA Products advisory that originally published on July 30th, 2020 and most recently updated on May 27th, 2021.

NOTE: NCCIC-ICS did not update their advisory (ICSA-20-212-03) for this information.

Mitsubishi Update #2 - Mitsubishi published an update for their Multiple FA Engineering Software Products advisory that was originally published on February 18th, 2021 and most recently updated on May 24th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-21-049-02) for this information.

Mitsubishi Update #3 - Mitsubishi published an update for their Multiple FA Engineering Software Products advisory that originally published on July 30th, 2020 and most recently updated on May 24th, 2022.

NOTE: NCCIC-ICS did not update their advisory (ICSA-20-212-04) for this information.

VMware Update - VMware published an update for their vCenter Server advisory that was originally published on July 12th, 2022.

Yokogawa Update #1 - Yokogawa published an update for their Wide Area Communication Router advisory that originally published on June 30th, 2022.

NOTE: NCCIC-ICS did not need to update their advisory (ICSA-22-181-02) for this information.

Yokogawa Update #2 - Yokogawa published an update for their CAMS for HIS advisory that was originally published on May 27th, 2022.

Yokogawa Update #3 - Yokogawa published an update for their OT:ICEFALL advisory that was originally published on June 21st. 2022. The new information includes adding fix for FCN/FCJ basic software.

NOTE: NCCIC-ICS did not update their advisory (ICSA-22-174-01) for this new information.

DD-WRT Report - Talos published a report that describes a memory corruption vulnerability in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599.

Asuswrt Report - Talos published a report that describes a memory corruption vulnerability in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.

FreshTomato Report - Talos published a report that describes a memory corruption vulnerability in the httpd unescape functionality of FreshTomato 2022.1

Nuki Report - NCC Group published a report that describes nine vulnerabilities in the Nuki smart locks.

Dingtian Exploit - Victor Hanna published an exploit for an authentication bypass vulnerability in the Dingtian-DT-R002 2Channel relay board.

Roxy-WI Exploit - Nuri Cilengir published a Metasploit module for a command injection vulnerability in the Roxy-WI web interface.

 

For more information on these disclosures, including summaries of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-7-23-9aa - subscription required.

Saturday, July 2, 2022

Review – Public ICS Disclosures – Week of 6-25-22 – Part 2

For Part 2 we have ten vendor updates for CODESYS (6), Dell, HP (3), and HPE. We have six researcher reports for products from Robustel (4), ExpressLRS, and Carel.

CODESYS Update #1 - CODESYS published an update for their Control V3 configuration file advisory that was that was originally published on March 24th, 2022, and most recently updated on June 10th, 2022.

CODESYS Update #2 - CODESYS published an update for their CODESYS communication protocol advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022

CODESYS Update #3 - CODESYS published an update for their Control V3 online user management advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V3 products containing a CODESYS communication server that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #5 - CODESYS published an update for their V3 web server advisory that was originally published on March 24th, 2022 and most recently updated on April 6th, 2022.

CODESYS Update #6 - CODESYS published an update for their V3 products containing a CODESYS communication server advisory that was originally published on May 19th, 2022 and most recently updated on May 30th, 2022.

Dell Update - Dell published an update for their Wyse ThinOS advisory that was originally published on July 21st, 2021.

HP Update #1 - HP published an update for their Intel® Boot Guard and Intel® TXT Security advisory that was originally published on May 10th, 2022.

HP Update #2 - HP published an update for their Intel 2022.1 IPU BIOS advisory that was originally published on July 21st, 2021.

HP Update #3 - HP published an update for their AMD Client UEFI Firmware advisory that was originally published on July 21st, 2021.

HPE Update - HPE published an update for their HP-UX Using OpenSSL advisory that was originally published on May 19th, 2022.

Robustel Reports – Cisco Talos published four reports for ten vulnerabilities in the Robustel R1510 web server.

ExpressLRS Report - NCC Group published a report describing a discoverable binding phrase for radio linkages in the ExpressLRS radio control link.

Carel Report - Zero Science published a report describing a directory traversal vulnerability in the Carel pCOWeb HVAC BACnet Gateway.

 

For more details on these updates and reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-2ec  - subscription required.

Saturday, June 18, 2022

Review – Public ICS Disclosures – Week of 6-11-22 – Part 2

For Part 2 we have nine vendor disclosures from Dell and Schneider (8). We also have four vendor updates for products from Fujitsu, Dell, HP, and HPE. We also have three researcher reports for products from Bachmann Visutec, Blynk, and Nexans. Part 3 tomorrow will cover Schneider and Siemens updates.

Dell Advisory - Dell published an advisory that discusses the SpringShell vulnerabilities.

Schneider Advisory #1 - Schneider published an advisory that describes two vulnerabilities in their EcoStruxure™ Cybersecurity Admin Expert.

Schneider Advisory #2 - Schneider published an advisory that describes an improper restriction of operations within the bounds of a memory buffer in their CanBRASS design and costing tool.

Schneider Advisory #3 - Schneider published an advisory that describes two vulnerabilities in their C-Bus Home Automation Products.

Schneider Advisory #4 - Schneider published an advisory that describes three vulnerabilities in their EcoStruxure Power Commission software.

Schneider Advisory #5 - Schneider published an advisory that describes three vulnerabilities in their Conext™ Combox communications and monitoring device.

Schneider Advisory #6 - Schneider published an advisory that describes an exposure of resource to wrong sphere vulnerability in their Geo SCADA Mobile application.

Schneider Advisory #7 - Schneider published an advisory that describes eight vulnerabilities in their Interactive Graphical SCADA System (IGSS).

Schneider Advisory #8 Schneider published an advisory that describes four vulnerabilities in their Data Center Expert product.

NOTE: This advisory was updated on June 16th, 2022. The new information included updating affected version information and clarification of fixed versions.

Fujitsu Update - JPCert published an update for the FUJITSU Network IPCOM advisory that was originally published on  May 19th, 2022 and most recently updated on June 10th, 2022.

Dell Update - Dell published an update for their Log4Shell advisory.

HP Update - HP published an update for their Wireless Bluetooth advisory that was originally published on February 8th, 2022.

HPE Update - HPE published an update for their Synergy Servers advisory that was originally published on May 10th, 2022 and most recently updated on May 31st, 2022.

Bachmann Report - Talos published a report describing an information disclosure vulnerability in the Bachmann Atvise SCADA registration function.

Blynk Report - Talos published a report describing a stack-based buffer overflow vulnerability in the Blynk-Library.

Nexans Report - SEC Consult published a report describing the four vulnerabilities in the Nexans FTTO GigaSwitch series due to using outdated software components.

 

For more details about these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-af5 - subscription required.

Saturday, March 5, 2022

Review - Public ICS Disclosures – Week of 2-26-22

This week we have twelve vendor disclosures from ABB, Beckhoff, Broadcom (2), B&R Automation, Delta Industrial Automation, Gerbv, OMRON, PcVue Solutions, Tanzu (2), and VMware. We also have two end-of-life notices from We have one researcher report for products from Swift Sensors. Finally, we have four exploits reported for products from WAGO, Hikvision, Axis, and the PwnKit vulnerability.

ABB Advisory - ABB published an advisory describing a denial of service vulnerability in their AC 800M MMS.

Beckhoff Advisory - Beckhoff published an advisory discussing a NULL pointer dereference vulnerability in their products with OPC UA technology.

NOTE: This vulnerability may be found in other vendor products utilizing OPC UA technology.

Broadcom Advisory #1 - Broadcom published an advisory discussing the LOGBACK-1591 vulnerability in their Brocade Fibre Channel Products.

Broadcom Advisory #2 - Broadcom published an advisory discussing the Log4Shell vulnerabilities.

B&R Advisory - B&R published an advisory discussing a deserialization of untrusted data vulnerability in their B&R APROL product line.

NOTE: This vulnerability may affect other vendor products that use Apache Chainsaw.

Delta Advisory - Incibe CERT published an advisory describing four vulnerabilities in the Delta CNCSoft ScreenEditor, and DIAEnergie products.

Gerbv Advisory - Incibe CERT published an advisory discussing seven vulnerabilities in the Gerbv file view.

Omron Advisory - JP CERT published an advisory describing five vulnerabilities in the OMRON CX-Programmer.

PcVue Advisory - PcVue published a notice discussing four vulnerabilities in their Dream Report products.

Tanzu Advisory #1 - Tanzu published an advisory describing an improper privilege management vulnerability in their Spring Cloud Gateway.

Tanzu Advisory #2 - Tanzu published an advisory describing a code injection vulnerability in their Spring Cloud Gateway.

VMware Advisory - VMware published an advisory describing an uncontrolled search path vulnerability in their VMware Tools for Windows.

Swift Sensor Report - Cisco Talos published a report describing an authentication bypass vulnerability in the Swift Sensor Gateway.

Braun End-of-Life Notices - Braun USA published end-of-life notices for their Dialog+ Version 8 and Dia70 Portable RO products.

WAGO Exploit - Momen Eldawakhly published an exploit for a privilege escalation vulnerability in the WAGO 750-8212 PFC200 G2 2ETH RS.

Hikvision Exploit - Bashis published a Metasploit module for a command injection vulnerability in unspecified Hikvision IP Camera.

Axis Exploit - Jbaines-r7 published a Metasploit module for an unrestricted upload of applications ‘feature’ in unspecified Axis IP cameras.

PwnKit Exploit - Qualys Security published a Metasploit module for the PwnKit vulnerability.

 

For more details about these disclosures, including links to third-party reports, researcher reports and exploits, see my article at CFSN Detailed Analysis - - subscription required.

Sunday, February 6, 2022

Review - Public ICS Disclosures – Week of 1-29-22 – Part 2

For Part 2 we have four more vendor disclosures from QNAP, TI, VMware, and Fujitsu. We also have five updates from Boston Scientific, Dell, Hillrom, Johnson Controls, and QNAP. There are also 98 researcher reports for vulnerabilities in products from Gerbv (2), and Bentley (96). Finally, we have three exploit reports for products from Moxa (2), and WAGO.

QNAP Advisory - QNAP published an advisory discussing the Deadbolt Ransomware attacks.

TI Advisory - TI published an advisory discussing physical security attacks on ‘silicon devices.’

VMware Advisory - VMware published an advisory describing an information disclosure vulnerability in their VMware Cloud Foundation.

Fujitsu Advisory - Fujitsu published an advisory discussing 15 vulnerabilities in Insyde® Firmware.

Boston Scientific Update - Boston Scientific published an update for their Log4Shell  advisory.

Dell Update - Dell published an update for their generic Log4Shell advisory.

Hillrom Update - Hillrom published an update for their Log4Shell advisory.

Johnson Controls Update - Johnson Controls published an update for their Log4Shell advisory.

QNAP Update - QNAP published an update for their QTS and QuTS hero advisory that was originally published on January 13th, 2021 and most recently updated on January 25th, 2022.

Gerbv Reports - Talos published two reports of vulnerabilities in the Gerbv RS-274X viewer.

Bentley Reports - The Zero Day Initiative published 96 reports (ZDI-22-149 thru ZDI-22-243ZDI) about vulnerabilities in the Bentley MicroStation and MicroStation-based applications.

Moxa Exploit #1 - Matthew Bergin published an exploit for a firmware upgrade vulnerability in the Moxa TN-5900.  

Moxa Exploit #2 - Matthew Bergin published an exploit for a command injection vulnerability vulnerability in the Moxa TN-5900.  

WAGO Exploit - Gerhard Hechenberger published an exploit for an improper handling of exceptional conditions vulnerability in the WAGO 750-8xxx PLC.

NOTE: This was reported as a third-party (CODESYS) vulnerability, so this exploit may work (with or without modification?) on other vendor products.

 

For more details on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-1-d73 - subscription required.

Saturday, December 25, 2021

Review - Public ICS Disclosure – Week of 12-18-21 – Part 1

Merry Christmas. This has been another busy week for ICS disclosures. Part 1 today will be normal vulnerabilities and Part 2 (probably tomorrow) will be Log4Shell disclosures.

This week we have six vendor disclosures from ABB, IDEC Corporation, QNAP, Hitachi Energy (2), and Johnson Controls. We also have twelve researcher reports for products from Garrett (7) and Open Design Alliance (5).

ABB Advisory - ABB published an advisory describing an MMS file transfer vulnerability in their Distribution Automation products.

IDEC Advisory - JPCERT published an advisory [link added 18:40 EST 1-6-22] for four vulnerabilities in the IDEC PLCs.

QNAP Advisory - JPCERT published an advisory describing two vulnerabilities in the QNAP VioStar series NVR.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory describing four vulnerabilities in their LinkOne product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisor discussing seven vulnerabilities in their Data Manager (SDM600) product.

Johnson Controls Advisory - Johnson Controls published an advisory describing an unspecified vulnerability in their American Dynamics VideoEdge NVR.

NOTE: It looks like this has been reported to NCCIC-ICS, so we may see an advisory from them next week

Garrett Reports - Talos published seven reports covering nine vulnerabilities in the Garrett Metal Detectors used for security screening.

ODA Reports - The Zero Day Initiative published five reports covering vulnerabilities in the ODA Drawings Explorer product.

For more details on these advisories, including links to third-party advisories, see my report at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-12 - subscription required.

Saturday, November 27, 2021

Review – Public ICS Disclosures – Week of 11-20-21

This week we have ten vendor disclosures from Advantech, Hitachi, Hitachi Energy (2), Moxa (2), QNAP (2), and VMware. There is also an update from Mitsubishi. Additionally, we have two researcher reports for vulnerabilities for products from PerFact and Philips. Finally, we have an exploit for a product from ModbusTools.

Advantech Advisory - Advantech published an advisory describing five sets of vulnerabilities (each set corresponding to a separate Talos report containing multiple vulnerabilities) in their R-SeeNet application.

Hitachi Advisory - Hitachi published an advisory discussing 24 vulnerabilities in their Disk Array Systems.

Hitachi Energy Advisory #1 - Hitachi Energy published an advisory describing two vulnerabilities in their XMC20 product.

Hitachi Energy Advisory #2 - Hitachi Energy published an advisory describing two vulnerabilities in their FOX61x product.

Moxa Advisory #1 - Moxa published an advisory describing eleven vulnerabilities in their ioLogik E2200 Series Controllers and I/Os.

Moxa Advisory #2 - Moxa published an advisory describing three vulnerabilities in their NPort IAW5000A-I/O Series Servers.

QNAP Advisory #1 - QNAP published an advisory describing an improper authentication vulnerability in their VS Series NVR.

QNAP Advisory #2 - QNAP published an advisory describing a command injection vulnerability in their VS Series NVR.

VMware Advisory - VMware published an advisory describing two vulnerabilities in their vCenter Server.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64 and MC Works64 advisory that was originally published on October 21st, 2021.

PerFact Report - Claroty published a report describing vulnerabilities in VPN products in use in industrial applications including a previously unpublished server-side request forgery vulnerability in products from PerFact.

Philips Report - Nozomi Networks published a report describing five vulnerabilities in patient monitoring products from Philips.

ModbusTools Exploit - Yehia Elghaly published an exploit for an improper restriction of operations within the bounds of a memory buffer vulnerabilty in the Modbus Slave tool from ModbusTools.

For more details on these advisories, updates, reports and exploits, including links to supporting third-party vulnerabilities, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-857 - subscription required.

 
/* Use this with templates/template-twocol.html */