Showing posts with label Western Digital. Show all posts
Showing posts with label Western Digital. Show all posts

Sunday, September 14, 2025

Review – Public ICS Disclosures – Week of 9-6-25 – Part 2

For Part 2 this week we have ten additional vendor disclosures from Philips, Phoenix Contact (2), Schneider (2), WAGO (3), Welotec, and Western Digital. We have bulk updates from Siemens (8). Finally, we have three other vendor updates from ABB.

Advisories

Philips Advisory - Philips published an advisory that discusses the Windows 10 end-of-life notice from Microsoft.

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory that discusses two vulnerabilities in their FL MGUARD product.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory that discusses a least privilege vulnerability in multiple Phoenix Contact products.

Schneider Advisory #1 - Schneider published an advisory that discusses a cross-site scripting vulnerability in their Altivar Process Drives and Communication Modules.

Schneider Advisory #2 - Schneider published an advisory that describes two vulnerabilities in their Saitel DR & Saitel DP remote terminal units.

WAGO Advisory #1 - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in multiple WAGO products.

WAGO Advisory #2 - CERT-VDE published an advisory that describes an incorrect permission assignment for critical resource vulnerability in multiple WAGO products.

WAGO Advisory #3 - CERT-VDE published an advisory that discusses an inclusion of functionality from untrusted control sphere vulnerability in multiple WAGO products.

Welotec Advisory - CERT-VDE published an advisory that describes a path traversal vulnerability in the Welotec SmartEMS Web Application.

Western Digital Advisory - Western Digital published an advisory that describes a root code execution vulnerability in their Acronis True Image for Western Digital (macOS).

Bulk Updates – Siemens

Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices,

Denial of Service Vulnerability in OpenSSL (CVE-2022-0778) Affecting Industrial Products,

Vulnerability in OPC Foundation Local Discovery Server Affecting Siemens Products,

Vulnerabilities in the BIOS of the SIMATIC S7-1500 TM MFP,

Multiple Vulnerabilities in Fortigate NGFW Before V7.4.1 on RUGGEDCOM APE1808 Devices,

Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products,

DLL Hijacking Vulnerability in Siemens Web Installer used by the Online Software Delivery, and

Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1

Updates

ABB Update #1 - ABB published an update for their RTU500 series advisory that was originally published on March 25, 2025, and most recently update on April 29th, 2025.

ABB Update #2 - ABB published an update for their RTU500 series advisory that was originally published on April 30th, 2024.

ABB Update #3 - ABB published an update for their RTU500 series advisory that was originally published on 26 March, 2024, and most recently updated on December 18th, 2024.

 

For more information on these disclosures, including links to researcher reports, 3rd party advisories, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-735 - subscription required.

Sunday, August 17, 2025

Review – Public ICS Disclosures – Week of 8-9-25 – Part 2

For Part 2 we have 15 additional vendor disclosures from Palo Alto Networks (6), Phoenix Contact, Schneider Electric (4), Siemens (2), Supermicro, and Western Digital. There are bulk updates from Siemens (23). We have additional 12 vendor updates from FortiGuard, HP (5), HPE, and Schneider (5). There are five researcher reports for vulnerabilities in products from Schneider (5). Finally, we have two exploits for products from Snort and VMware.

Advisories

Palo Alto Networks Advisory #1 - PAN published an advisory that discusses six vulnerabilities in their Prisma Access Browser.

Palo Alto Networks Advisory #2 - PAN published an advisory that describes a deserialization of untrusted data vulnerability in their Checkov by Prisma Cloud product.

Palo Alto Networks Advisory #3 - PAN published an advisory that describes a cleartext exposure of sensitive information vulnerability in their Checkov by Prisma Cloud.

Palo Alto Networks Advisory #4 - PAN published an advisory that describes a cleartext storage of sensitive information vulnerability in multiple PAN products.

Palo Alto Networks Advisory #5 – PAN published an advisory that describes an improper certificate validation vulnerability in their GlobalProtect App.

Palo Alto Networks Advisory #6 – PAN  published an advisory that describes a use of default credentials vulnerability in their Cortex XDR Broker VM. - PAN published an advisory that describes a use of default credentials vulnerability in their Cortex XDR Broker VM.

Phoenix Contact Advisory - Phoenix Contact published an advisory that describes a missing authentication for critical function vulnerability in their Device and Update Management service.

Schneider Advisory #1 - Schneider published an advisory that describes an improper privilege management vulnerability in their Saitel DR & Saitel DP RTU products.

Schneider Advisory #2 - Schneider published an advisory that describes a link following vulnerability in their Software Update (SESU) product.

Schneider Advisory #3 - Schneider published an advisory that describes two vulnerabilities in their EcoStructure Building Operation products.

Schneider Advisory #4 - Schneider published an advisory that describes an improper input validation vulnerability in multiple Schneider products.

Siemens Advisory #1 - Siemens published an advisory that describes an improper verification of cryptographic signature vulnerability in their Mendix SAML products.

Siemens Advisory #2 - Siemens published an advisory that describes least privilege violation in multiple Siemens products.

Supermicro Advisory - Supermicro published an advisory that discusses two vulnerabilities in multiple Supermicro products.

Western Digital Advisory - Western Digital published an advisory that describes a Windows registration vulnerability in their Kitfox Software for Windows.

Bulk Updates

Siemens published 23 updates.

Updates

FortiGuard Update - FortiGuard published an update for their OpenSSH advisory that was originally published on March 11th, 2025, and most recently updated on May 13th, 2025. The new information includes updating version and SoftPaq information for Business Desktops.

HP Update #1 - FortiGuard published an update for their OpenSSH advisory that was originally published on March 11th, 2025, and most recently updated on May 13th, 2025.

HP Update #2 - HP published an update for their NVIDIA GPU Display Driver advisory that was originally published on March 31st, 2025. 

HP Update #3 - HP published an update for their AMD SMM Vulnerabilities advisory that was originally published on May 7th, 2025.

HP Update #4 - HP published an update for their AMD Client Processors advisory that was originally published on February 11th, 2025.

HP Update #5 - HP published an update for their Intel Graphics Software advisory that was originally published on February 11th, 2025.

HPE Update #1 - HPE published an update for their Private Cloud AI advisory that was originally published on August 8th, 2025.

HPE Update #2 - HPE published an update for their SANnav Management Portal advisory that was originally published on July 8th, 2025.

Schneider Update #1 - Schneider published an update for their BadAlloc advisory that was originally published on November 9th, 2021, and most recently updated on April 8th, 2025.

Schneider Update #2 - Schneider published an update for their CODESYS Runtime advisory that was originally published on July 11th, 2023, and most recently updated on June 11th, 2024.

Schneider Update #3 - Schneider published an update for their Web Server on Modicon M340 advisory that was originally published on January 14th, 2025.

Schneider Update #4 - Schneider published an update for their Wind River VxWorks DHCP server advisory that was originally published on January 14th, 2025, and most recently updated on April 8th, 2025.

Schneider Update #5 - Schneider published an update for their Modicon M340 advisory that was originally published on June 11th, 2024.

Researcher Reports

Schneider Reports - ZDI published five reports of individual vulnerabilities in the Schneider EcoStruxure Power Monitoring Expert.

Exploits

Snort Exploit - Rapid7 published a Metasploit module for an OS command injection vulnerability in the Snort Report product.

VMware Exploit - Imraan Khan published an exploit for a cross-site scripting vulnerability in the VMware vSphere Client.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis, including links to 3rd party advisories as well as a list of the individual updates in the bulk update - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-2a7 - subscription required.

Sunday, May 4, 2025

Review – Public ICS Disclosures – Week of 4-26-25 – Part 2

For Part 2 this week we have three additional vendor disclosures from Splunk, Western Digital, and Wiesemann and Theis. There are also two vendor updates from Hitachi Energy and Palo Alto Networks. We also have nine researcher reports about vulnerabilities in products from Daikin, HP Wolf, Tesla (6), and SonicWall.

Advisories

Splunk Advisory - Splunk published an advisory that discusses 13+ vulnerabilities (six with publicly available exploits) in their User Behavior Analytics product.

Western Digital Advisory - Western Digital published an advisory that discusses 12 vulnerabilities (six with publicly available exploits) in their My Cloud devices.

Wiesemann Advisory - CERT-VDE published an advisory that describes the use of a broken or risky cryptographic algorithm vulnerability in the Wiesemann and Theis Com-Server products.

Updates

Hitachi Energy Update - Hitachi Energy published an update that provides additional information on their RTU500 series advisory that was originally published on March 25th, 2025.

Palo Alto Networks Update - Palo Alto Networks published an update for their GlobalProtect App advisory that was originally published on April 9th, 2025, and most recently updated on April 21st, 2025.

Researcher Reports

Daikin Report - Zero Science published a report that describes an insecure direct object reference vulnerability in the Daikin Security Gateway.

HP Wolf Report - SEC Consult published a report that describes a CSRF vulnerability in the HP Wolf Security Controller, as well as multiple misconfiguration issues.

Tesla Reports - ZDI published six reports about individual vulnerabilities in the Tesla Model S.

SonicWall Report - BishopFox published a report that describes a denial of service vulnerability in the SonicWall Sonic OS product.

 

For more information on these disclosures, including links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-d05 - subscription required.

Saturday, December 21, 2024

Review – Public ICS Disclosures – Week of 12-14-24

This week we have 13 vendor disclosures from Dassault Systèmes (4), FortiGuard Labs, GE Vernova (3), Hitachi (3), HPE (2), Meinberg, and Western Digital. We have 11 vendor updates from FortiGuard, Hitachi Energy (8), and Palo Alto Networks. There are also five researcher reports describing vulnerabilities in products from ABB, Delta Electronics (3), and Rockwell Automation. Finally, we have an exploit report for products from FLIR.

Advisories

Dassault Advisory #1 - Dassault published an advisory that describes a cross-site scripting vulnerability in their ENOVIA Collaborative Industry Innovator.

Dassault Advisory #2 - Dassault published an advisory that describes a cross-site scripting vulnerability in their ENOVIA Collaborative Industry Innovator.

Dassault Advisory #3 - Dassault published an advisory that describes a cross-site scripting vulnerability in their ENOVIA Collaborative Industry Innovator.

Dassault Advisory #4 - Dassault published an advisory that describes a cross-site scripting vulnerability in their ENOVIA Collaborative Industry Innovator.

FortiGuard Advisory - FortiGuard published an advisory that describes an OS command injection vulnerability in their FortiManager product.

GE Vernova Advisory #1 - GE published an advisory that discusses two vulnerabilities (both listed in CISA’s Known Exploited Vulnerability catalog) in their Control Server installations utilizing VMware vCenter Server.

GE Vernova Advisory #2 - GE published an advisory that discusses two vulnerabilities (both listed in CISA’s KEV catalog) in their  engineering workstations with Veeam Backup & Replication 9.5, 10, or 11 installed.

GE Vernova Advisory #3 - GE published an advisory that discusses six vulnerabilities (one with publicly available exploit) in their e UCSE, UCSC, and UCSB controllers utilized in the Mark* VIe Platform.

Hitachi Advisory #1 - Hitachi published an advisory that discusses 19 vulnerabilities in their Ops Center Common Services.

Hitachi Advisory #2 - Hitachi published an advisory that describes a missing authentication for critical function vulnerability in their Infrastructure Analytics Advisor and Ops Center Analyzer products.

Hitachi Advisory #3 - Hitachi published an advisory that discusses 56 vulnerabilities in multiple Hitachi products.

HPE Advisory #1 - HPE published an advisory that discusses an improper authentication vulnerability in their SANnav Management Portal.

HPE Advisory #2 - HPE published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their Alletra MP OS.

Meinberg Advisory - Meinberg published an advisory that discusses four vulnerabilities (one with publicly available exploit) in their Lantime product.

Western Digital Advisory - Western Digital published an advisory that discusses three vulnerabilities in their My Cloud Home & Duo products.

Updates

FortiGuard Update - FortiGuard published an update for their regreSSHion advisory that was originally published on July 9th, 2024, and most recently updated on December 4th, 2024.

Hitachi Energy Update #1 - Hitachi Energy published an update for their Modbus TCP Packet advisory that was originally published on April 19th, 2022, and most recently updated on September 24th, 2024.

Hitachi Energy Update #2 - Hitachi Energy published an update for their RTU500 Series Product advisory that was originally published on March 25th, 2023, and most recently updated on October 1st, 2024.

Hitachi Energy Update #3 - Hitachi Energy published an update for their RTU500 series products advisory that was originally published on December 19th, 2023, and most recently updated on September 24th, 2024.

Hitachi Energy Update #4 - Hitachi Energy published an update for their RTU500 series Product advisory that was originally published on March 26th, 2024, and most recently updated on October 1st, 2024.

Hitachi Energy Update #5 - Hitachi Energy published an update for their RTU500 series Product advisory that was originally published on April 25th, 2024, and most recently updated on October 1st, 2024.

Hitachi Energy Update #6 - Hitachi Energy published an update for their RTU500 series Product that was originally published on June 28th, 2022, and most recently updated on September 24th, 2024.

Hitachi Energy Update #7 - Hitachi Energy published an update for their RTU500 series Product that was originally published on November 28th, 2023, and most recently updated on October 1st, 2024.

Hitachi Energy Update #8 - Hitachi Energy published an update for their RTU500 series Product that was originally published on February 14th, 2023, and most recently updated on October 1st, 2024.

Palo Alto Networks Update - Palo Alto Networks published an update for their GlobalProtect App advisory that was originally published on November 25th, 2024, and most recently updated on December 13th, 2024.

Researcher Reports

ABB Report - Zero Science published a report that describes an authentication bypass vulnerability (with a publicly available exploit) in the ABB Cylon Aspect building energy management product.

Delta Reports - The Zero Day Initiative published three reports for vulnerabilities in the Delta Electronics DRASimuCAD.

Rockwell Report - ZDI published a report that describes an out-of-bounds write vulnerability in the Rockwell Arena Simulation product.

Exploit

FLIR Exploit - YZS17 published an exploit for a command injection vulnerability in the FLIR AX8 thermal imaging camera.

 

For more information about these notifications, to include links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-3dd   - subscription required.

Sunday, November 3, 2024

Review – Public ICS Disclosures – Week of 10-25-24 – Part 2

For Part 2 this week we have nine additional vendor disclosures from Moxa, Palo Alto Networks, Philips (3), QNAP (2), Western Digital, and Zyxel. There are six vendor updates from FortiGuard, Hitachi Energy (4), and Moxa. We also have 12 researcher reports for vulnerabilities in products from FortiGuard and ABB (11).

Advisories

Moxa Advisory - Moxa published an advisory that discusses two vulnerabilities (both with publicly available exploits) in their Ethernet Switches.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses 42 open-source software vulnerabilities.

Philips Advisory #1 - Philips published an advisory that discusses a missing authentication for critical function vulnerability.

Philips Advisory #2 - Philips published an advisory that discusses an SQL injection vulnerability.

Philips Advisory #3 - Philips published an advisory that discusses an improper neutralization of expression/command delimiters vulnerability.

QNAP Advisory #1 - QNAP published an advisory that describes an uncharacterized vulnerability in their HBS 3 Hybrid Backup Sync.

QNAP Advisory #2 - QNAP published an advisory that describes an uncharacterized vulnerability in their SMB Service.

Western Digital Advisory - Western Digital published a security update notice for their My Cloud products.

Zyxel Advisory - Zyxel published an advisory that describes an insufficiently protected credentials vulnerability in their USG FLEX H series firewalls.

Updates

FortiGuard Update - FortiGuard published an update for their Missing authentication in fgfmsd advisory that was originally published on October 23rd, 2024, and most recently updated on October 28th.

Hitachi Energy Update #1 - Hitachi Energy published an update for their FOXMAN-UN advisory that was originally published on June 11th, 2024.

Hitachi Energy Update #2 - Hitachi Energy published an update for their UNEM advisory that was originally published on June 11th, 2024.

Hitachi Energy Update #3 - Hitachi Energy published an update for their MSM product advisory that was originally published on January 30th, 2024.

Hitachi Energy Update #4 - Hitachi Energy published an update for their MicroSCADA advisory that was originally published on August 27th, 2024, and most recently updated on August 30th, 2024.

Moxa Update - Moxa published an update for their Cellular Routers, Secure Routers, and Network Security Appliances advisory that was originally published on October 14th, 2024 and most recently updated on October 15th, 2024.

Researcher Reports

FortiGuard Report - Bishop Fox published a report on the missing authentication for critical function vulnerability (CVE-2024-47575) for FortiGuard’s FortiManager product.

ABB Reports - Zero Science published eleven reports about individual vulnerabilities (with publicly available exploits) in the ABB Cylon Aspect building energy management product.

 

For more information on these vulnerabilities, including links to 3rd party advisories, researcher reports, and exploits, as well as brief summaries of the changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-10-a32 - subscription required.

Saturday, September 28, 2024

Review – Public ICS Disclosures – Week of 9-21-24

This week we have 17 vendor disclosures from Broadcom (2), Cisco, GE Vernova, HPE (5), Palo Alto Networks, SEL, SICK, WatchGuard (3), Western Digital, and Zyxel. There are also 3 updates from CODESYS, ELECOM, and HPE. We also have 6 researcher reports for products from ABB (4), Blackberry, and Linear Solutions. Finally, we have 3 exploits for products from BlackNET, Positron, and Texas Instruments.

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses the Blast-Radius vulnerability.

Broadcom Advisory #2 - Broadcom published version release notice for their Brocade Fabric OS that lists the previously disclosed vulnerabilities that are corrected in the latest version.

Cisco Advisory - Cisco published an advisory that describes an improper access control vulnerability in their Industrial Ethernet 4000, 4010, and 5000 Series Switches.

GE Vernova Advisory - GE published an advisory that describes two vulnerabilities in their WorkstationST products.

HPE Advisory #1 - HPE published an advisory that discusses the regreSSHion vulnerability in their HPE Superdome Flex and Superdome Flex 280 servers.

HPE Advisory #2 - HPE published an advisory that describes three command injection vulnerabilities in their Aruba Access Points products.

HPE Advisory #3 - HPE published an advisory that describes a cross-site request forgery vulnerability in their IceWall Agent products.

HPE Advisory #4 - HPE published an advisory that discusses a protection mechanism failure vulnerability in their SimpliVity Servers.

HPE Advisory #5 - HPE published an advisory that discusses an inconsistent flow control management vulnerability in their SimpliVity Servers.

Palo Alto Networks Advisory - Palo Alto Networks published an advisory that discusses the CUPS vulnerabilities.

SEL Advisory - SEL published a new version notice for their SEL-5033 acSELerator RTAC software that describes a cybersecurity enhancement.

SICK Advisory - SICK published an advisory that describes a missing authentication for critical function vulnerability in their MSC800 track and trace controller.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes an incorrect authorization vulnerability (with publicly available exploit) in their Authentication Gateway.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes an incorrect authorization vulnerability (with publicly available exploit) in their Authentication Gateway.

WatchGuard Advisory #3 - WatchGuard published an advisory that describes an improper handling of exceptional or unusual conditions vulnerability (with publicly available exploit) in their Single Sign-On Client.

Western Digital Advisory - Western Digital published an advisory that describes an improper restriction of operations within the bounds of a memory buffer vulnerability in their My Cloud firmware.

Zyxel Advisory - Zyxel published an advisory that describes four improper restriction of operations within the bounds of a memory buffer vulnerabilities in multiple Zyxel products.

Updates

CODESYS Update - CODESYS published an update for their Control V3 web server advisory that was originally published on August 29th, 2024.

ELECOM Update - JP-CERT published an update for their ELECOM wireless LAN advisory that was originally published on August 27th, 2024.

HPE Update - HPE published an update for their ProLiant DL/ML/XL, Edgeline, MicroServer and Synergy Servers advisory that was originally published on September 16th, 2024 and most recently updated on September 19th, 2024.

Researcher Reports

ABB Report #1 - Zero Science published a report that describes a files or directories accessible to external parties vulnerability (with an associated exploit) in the ABB ASPECT building management software.

ABB Report #2 - Zero Science published a report that describes an improper input validation vulnerability (with an associated exploit) in the ABB ASPECT building management software.

ABB Report #3 - Zero Science published a report that describes a command injection vulnerability (with an associated exploit) in the ABB ASPECT Control Engines.

ABB Report #4 - Zero Science published a report that describes a use of default credentials vulnerability (with an associated exploit) in the ABB ASPECT system.

Blackberry Report - SEC Consult published a report that describes an authentication bypass by alternate path or channel vulnerability in the Blackberry CylanceOPTICS Windows Installer Package.

Linear Solutions Report - SSD published a report that describes a remote code execution vulnerability in the Linear eMerge E3 access control product.

Exploits

BlackNET Exploit - bRpsd published an exploit for a missing authentication for critical operation vulnerability in the BlackNET secure transport layer.

Positron Exploit - Indoushka published an exploit for a cross-site request forgery in the Positron Broadcast Signal Processor TRA7005.

TI Exploit - crypt0d1v3r published a proof-of-concept toolkit for a denial of service vulnerability in the TI bluetooth stack.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-2c2 - subscription required.

Saturday, August 3, 2024

Review – Public ICS Disclosures – Week of 8-27-24

This week we have six vendor disclosures for the regreSSHion vulnerability from Cisco, Eaton, Helmholtz, HPE, Moxa, and Red Lion. We have nine additional vendor disclosures from ABB, Broadcom (4), HP, HPE (2), and Western Digital. There are also four vendor updates from Broadcom, Cisco, Hitachi Energy, and HPE. We also have two researcher reports for products from FortiGuard and Pioneer. Finally, we have an exploit for products from mySCADA.

RegreSSHion Advisories

Cisco published an update for their regreSSHion advisory that was originally published on July 2nd, 2024 and most recently updated on July 26th, 2024.

Eaton published an advisory that announces that Eaton is investigating the vulnerability, but notes that for most Eaton products, SSH service is disable by default.

Helmholtz – CERT-VDE published an advisory that provides a list of affected products and fixed versions.

HPE published an update for their regreSSHion advisory that was originally published on July 10th, 2024.

Moxa published an advisory that provides a list of affected and fixed products.

Red Lion Europe – CERT-VDE published an advisory that provides a list of affected products and fixed versions.

Advisories

ABB Advisory - ABB published an advisory that discusses an insufficiently protected credentials vulnerability in their Automation Builder product.

Broadcom Advisory #1 - Broadcom published an advisory that discusses five vulnerabilities (3 with exploits available) in their Brocade Fabric OS.

Broadcom Advisory #2 - Broadcom published an advisory that discusses nine vulnerabilities (2 with exploit code available) in multiple Broadcom products.

Broadcom Advisory #3 - Broadcom published an advisory that describes a command injection vulnerability in their Brocade 6547 (FC5022) embedded switches.

Broadcom Advisory #4 - Broadcom published an advisory that describes a plain-text storage of passwords vulnerability in their Brocade FabricOS.

HMS Advisory - HMS published an advisory that describes six vulnerabilities in their Cosy+ product line.

HP Advisory - HP published an advisory that discusses 214 vulnerabilities in their ThinPro products.

HPE Advisory #1 - HPE published an advisory that discusses 16 vulnerabilities (5 with publicly available exploits) in their Fiber Channel and SAN Switches.

HPE Advisory #2 - HPE published an advisory that discusses four vulnerabilities (one with publicly available exploits) in their Aruba ClearPass Policy Manager product.

Western Digital Advisory - Western Digital published an advisory that describes a code injection vulnerability in their Discovery Desktop App.

Updates

Broadcom Update - Broadcom published an update for their Azul Zulu advisory that was originally published on July 26th, 2024.

Cisco Update - Cisco published an update for their RADIUS Protocol Spoofing advisory that was originally published on July 10th, 2024 and most recently updated on July 29th, 2024.

Hitachi Energy Update - Hitachi Energy published an update for their IED ConnPacks advisory that was originally published on November 15th, 2022 and most recently updated on June 25th, 2024.

HPE Update - HPE published an update for their Telecommunication Management Information Platform advisory that was originally published on December 12th, 2024.

Researcher Reports

FortiGuard Report - IOActive published a report describing a cross-site scripting vulnerability in the FortiGuard SSL VPN web UI.

Pioneer Report - ZDI published three reports of individual vulnerabilities in the Pioneer DMH-WT7600NEX automotive media center.

Exploits

MySCADA Exploit - Michael Heinzl published a Metasploit module for an OS command injection vulnerability in the mySCADA MyPro product.

 

For more details about these disclosures, including links to 3rd party vendors, see my article at CFSN Detailed analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-dae - subscription required.

Saturday, June 15, 2024

Review – Public ICS Disclosures – Week of 6-8-24 – Part 2

For Part 2 we have nine additional vendor disclosures from Schneider Electric (5), Siemens, VMware, Western Digital, and ZKTeco. We also have 28 vendor updates from HP (13), Schneider (2), and Siemens (13). In Part 3 we will look at researcher reports and exploits.

Advisories

Schneider Advisory #1 - Schneider published an advisory that describes a files or directories accessible to external parties vulnerability in their Modicon M340 and BMXNOE0100 and BMXNOE0110 products.

Schneider Advisory #2 - Schneider published an advisory that describes a use of broken or risky cryptographic algorithm vulnerability.

Schneider Advisory #3 - Schneider published an advisory that describes an exposure of resource to wrong sphere vulnerability in their EVlink Home Smart product.

Schneider Advisory #4 - Schneider published an advisory that describes a TOCTOU race condition in their SpaceLogic AS-P and AS-B products.

Schneider Advisory #5 - Schneider published an advisory that describes six vulnerabilities in their SAGE RTU products.

Siemens Advisory - Siemens published an advisory that describes an incorrect type conversion or cast vulnerability in their Tecnomatix Plant Simulation product.

VMware Advisory - VMware published an advisory that describes three vulnerabilities in their SD-WAN Edge and SD-WAN Orchestrator products.

Western Digital Advisory - Western Digital published an advisory that describes a cross-site scripting vulnerability in multiple Western Digital products.

ZKTeco Advisory - ZKTeco published an advisory that announced that they had a firmware update that “addresses minor vulnerabilities identified in certain models of our standalone terminals”.

Updates

HP Update #1 - HP published an update for their Aruba 9200 and 9000 Series Controllers advisory that was originally published on September 6th, 2023.

HP Update #2 - HP published an update for their Aruba ClearPass Policy Manager advisory that was originally published on October 24th, 2023.

HP Update #3 - HP published an update for their Aruba AirWave Management Platform advisory that was originally published on October 17th, 2023 and most recently updated on October 23rd, 2023.

HP Update #4 - HP published an update for their ArubaOS-Switch Switches advisory that was originally published on August 29th, 2023.

HP Update #5 - HP published an update for their Aruba EdgeConnect SD-WAN Orchestrator advisory that was originally published on August 22nd, 2023 and most recently updated on October 3rd, 2023.

HP Update #6 - HP published an update for their Aruba Networking Virtual Intranet Access advisory that was originally published on August 15th, 2023.

HP Update #7 - HP published an update for their Aruba CX Switches advisory that was originally published on August 1st, 2023.

HP Update #8 - HP published an update for their Aruba Access Points advisory that was originally published on July 25th, 2023.

HP Update #9 - HP published an update for their ArubaOS advisory that was originally published on July 11th, 2023.

HP Update #10 - HP published an update for their Aruba EdgeConnect Enterprise advisory that was originally published on May 24th, 2023.

HP Update #11 - HP published an update for their Aruba Access Points advisory that was originally published on May 9th, 2023.

HP Update #12 - HP published an update for their Aruba Bypassing Wi-Fi Encryption advisory that was originally published on April 4th, 2023, and most recently updated on April 6th, 2023.

HP Update #13 - HP published an update for their ProLiant DL/DX/ML/SY/RL/XL/Edgeline Servers advisory that was originally published on April 2nd, 2024 and most recently updated on June 3rd, 2024.

Schneider Update #1 - Schneider published an update for their CODESYS Runtime advisory that was originally published on July 11th, 2023, and most recently updated on April 9th, 2024.

Schneider Update #2 - Schneider published an update for their Easy UPS advisory that was originally published on April 11th, 2023, and most recently updated on June 13th, 2023.

Siemens Update #1 - Siemens published an update for their SICAM Products advisory that was originally published on May 14th, 2024.

Siemens Update #2 - Siemens published an update for their RUGGEDCOM APE1808 advisory that was originally published on March 12th, 2024, and most recently updated on May 14th, 2024.

Siemens Update #3 - Siemens published an update for their SIMATIC WinCC advisory that was originally published on February 13th, 2024, and most recently updated on April 9th, 2024.

Siemens Update #4 - Siemens published an update for their OPC UA Implementations advisory that was originally published on September 12th, 2023, and most recently updated on May 14th, 2024.

Siemens Update #5 - Siemens published an update for their Profinet Devices advisory that was originally published on July 13th, 2021, and most recently updated on April 12th, 2024.

Siemens Update #6 - Siemens published an update for their Webserver of Industrial Products advisory that was originally published on April 11th, 2023, and most recently updated on May 9th, 2023.

Siemens Update #7 - Siemens published an update for their n S7-1500 CPU Devices advisory that was originally published on January 10th, 2023, and most recently updated on December 12th, 2023.

Siemens Update #8 - Siemens published an update for their PROFINET Stack advisory that was originally published on April 12th, 2022, and most recently updated on May 14th, 2024.

Siemens Update #9 - Siemens published an update for their Parasolid and Teamcenter Visualization advisory that was originally published on August 8th, 2023, and most recently updated on November 14th, 2023.

Siemens Advisory # 10 - Siemens published an update for their GNU/Linux Subsystem advisory that was originally published on December 12th, 2023, and most recently updated on May 14th, 2024.

Siemens Advisory #11 - Siemens published an update for their SCALANCE XB-200 advisory that was originally published on March 12th, 2024.

Siemens Advisory #12 - Siemens published an update for their SIMATIC RTLS advisory that was originally published on May 14th, 2024.

Siemens Advisory #13 - Siemens published an update for their SICAM PAS/PQS advisory that was originally published on October 10th, 2023.

 

For more information on these disclosures, including links to 3rd party advisories and brief summaries of changes made in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-f31 - subscription required.

Saturday, March 16, 2024

Review – Public ICS Disclosures – Week of 2-9-24 – Part 2

For Part 2 we have four additional vendor disclosures from Schneider, Softing, WAGO, and Western Digital. We also have 17 vendor updates from Dell, HP (5), and Siemens (11). There is a researcher report about vulnerabilities in products from FortiGuard. Finally, we have five exploits for products from FortiGuard, Hitachi, Honeywell, Solar View, and VMware.

Advisories

Schneider Advisory - Schneider published an advisory that describes three vulnerabilities in their Easergy T200 RTU product line.

Softing Advisory - Softing published an advisory that describes a missing release of memory after effective lifetime vulnerability in their UA Toolkit and smartLink products.

WAGO Advisory - CERT-VDE published an advisory that describes two vulnerabilities in the WAGO 750-8xx series PLCs.

Western Digital - Western Digital published an advisory that describes an uncontrolled search path element vulnerability in their SanDisk PrivateAccess Desktop App.

Updates

Dell Updates - Dell published an update for their Wyse Password Encoder advisory that was originally published on February 1st, 2019.

HP Update #1 - HP published an update for their Intel 2023.4 IPU advisory that was originally published on December 11th, 2023.

HP Update #2 - HP published an update for their AMI UEFI Firmware advisory that was originally published on January 26th, 2024.

HP Update #3 - HP published an update for their Intel Graphics Drivers advisory that was originally published on November 15th, 2023.

HP Update #4 - HP published an update for their AMD SMM Supervisor advisory that was originally published on December 7th, 2023.

HP Update #5 - HP published an update for their AMD Client UEFI Firmware advisory that was originally published on January 8th, 2024.

Siemens Update #1 - Siemens published an update for their n SIMATIC STEP 7 advisory that was originally published on June 13th, 2023.

Siemens Update #2 - Siemens published an update for their SINEC NMS advisory that was originally published on February 13th, 2023.

Siemens Update #3 - Siemens published an update for their Polarion ALM advisory that was originally published on February 13th, 2024.

Siemens Update #4 - Siemens published an update for their e OPC UA Implementation advisory that was originally published on September 12th, 2023 and most recently updated on February 13th, 2024.

Siemens Update #5 - Siemens published an update for their Web Server of Industrial Products Advisory that was originally published on December 12, 2023.

Siemens Update #6 - Siemens published an update for their SIMATIC S7-1500 CPUs advisory that was originally published on December 12th, 2023.

Siemens Update #7 - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on December 13th, 2022 and most recently updated on September 12th, 2023.

Siemens Update #8 - Siemens published an update for their GNU/Linux subsystem advisory that was originally published on December 12th, 2023 and most recently updated on February 13th, 2024.

Siemens Update #9 - Siemens published an update for their SCALANCE XB-200 / XC-200 / XP-200 / XF-200BA / XR-300WG Family that was originally published on November 14th, 2023 and most recently updated on December 12th, 2023.

Siemens Update #10 - Siemens published an update for their SIPROTEC 5 Devices advisory that was originally published on April 11th, 2023 and most recently updated on September 12, 2023.

Siemens Update #11 - Siemens published an update for their Simcenter Femap advisory that was originally published on February 13th, 2024.

Researcher Reports

FortiGuard Report - Horizon3 published a report describing six vulnerabilities in the Fortinet FortiWLM product.

Exploits

FortiGuard Exploit - H4x0r-dz published an exploit for an out-of-bounds write vulnerability that is on the CISA Known Exploited Vulnerabilities Catalog.

Hitachi Exploit - Arslan Masood published an exploit for an improper authentication vulnerability in the Hitachi NAS.

Honeywell Exploit - BYTEHUNTER published an exploit for a command injection vulnerability in the Honeywell PM43 industrial printers.

Solar View Exploit - BYTEHUNTER published an exploit for a command injection vulnerability in the Solar View compact product.

VMware Exploit - Abdualhadi Khalifa published an exploit for a missing authentication for critical function vulnerability in the VMware Cloud Director.

 

For more information on these disclosures, including a brief description of changes in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-5d3 - subscription required.

Saturday, March 9, 2024

Review – Public ICS Disclosures – Week of 3-2-24

This week we have 12 vendor disclosures from Aruba Networks, Commend, Moxa, Omron, QNAP (5), SEL, VMware (2), and Western Digital. There are four vendor updates from Cisco and HP (3). We also have three researcher reports of vulnerabilities for products from Lenovo. Finally, we have five exploits for Petrol Pump (3), RAD, and Solar-Log.

Advisories

Aruba Advisory - Aruba published an advisory that describes seven vulnerabilities in their ArubaOS products.

Commend Advisory - Commend published an advisory that describes three vulnerabilities in their WS-TM monitor firmware.

Moxa Advisory - Moxa published an advisory that describes a stack-based buffer overflow vulnerability in their NPort W2150A/W2250A Series web server.

Omron Advisory - Omron published an advisory that describes a path traversal vulnerability in their NJ/NX-series Machine

Automation Controllers.-

QNAP Advisory #1 - QNAP published an advisory that describes a path traversal vulnerability in their Photo Station product.

QNAP Advisory #2 - QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes a cross-site scripting vulnerability in their Network & Virtual Switch products.

QNAP Advisory #4 - QNAP published an advisory that discusses four vulnerabilities in their QuMagie Mobile 2.2.x for Android product.

QNAP Advisory #5 - QNAP published an advisory that describes three vulnerabilities in their QTS, QuTS hero, QuTScloud, and myQNAPcloud products.

SEL Advisory - SEL published an announcement that the latest version of their SEL-5030 acSELerator QuickSet Software addresses a number of undescribed cybersecurity issues.

VMware Advisory #1 - VMware published an advisory that describes four vulnerabilities in their ESXi, Workstation, and Fusion products.

VMware Advisory #2 - VMware published an advisory that describes a partial information disclosure vulnerability in their VMware Cloud Director product.

Western Digital Advisory - Western Digital published an advisory that describes a DLL hijacking vulnerability in their SanDisk PrivateAccess product.

Updates

Cisco Update - Cisco published an update for their cURL advisory that was originally published on October 12th, 2023 and most recently updated on February 21st, 2024.

HP Update #1 - HP published an update for their UC software advisory that was originally published on January 9th, 2024.

HP Update #2 - HP published an update for their UC software advisory that was originally published on January 8th, 2024.

HP Update #3 - HP published an update for their UC Software advisory that was originally published on January 9th, 2023 and most recently updated on February 9th, 2024.

Researcher Reports

Lenovo Report #1 - Binarly published a report describing an unsanitized arguments vulnerability in the Lenovo J1CN38WW.

Lenovo Report #2 - Binarly published a report describing an out-of-bounds write vulnerability in the Lenovo J1CN38WW.

Lenovo Report #3 - Binarly published a report describing an out-of-bounds write vulnerability in the Lenovo J1CN38WW.

Exploits

Petrol Pump Exploit #1 - Shubham Pandey published an exploit for two cross-site scripting vulnerabilities in the Petrol Pump management software.

Petrol Pump Exploit #2 - Shubham Pandey published an exploit for an SQL injection vulnerability in the Petrol Pump management software.

Petrol Pump Exploit #3 - Shubham Pandey published an exploit for a shell upload vulnerability in the Petrol Pump management software.

RAD Exploit - Branko Milicevic published an exploit for a directory traversal vulnerability in the RAD SecFlow-2 devices.

Solar-Log Exploit - Mesut Cetin published an exploit for a cross-site scripting vulnerability in the Solar-Log 200 PM+ product.

 

For more details about these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-3-205  - subscription required.

Saturday, February 10, 2024

Review – Public ICS Disclosure – Week of 2-3-24

This week we have 22 vendor disclosures from Badger, B&R Automation (2), FortiGuard (4), GE Vernova, Hitachi (2), HPE, Meinberg, Pilz, SEL, Sharp, VMware, WatchGuard (4), and Western Digital. There is also one update from HP. Finally, we have three exploits for products from Forta, Milesight, and Zyxel.

Advisories

Badger Advisory - Incibe-CERT published an advisory that describes four vulnerabilities in their Monitool product.

B&R Advisory #1 - B&R published an advisory that describes a use of broken or risky cryptographic algorithm in their Runtime FTP server component.

B&R Advisory #2 - B&R published an advisory that describes a cross-site scripting vulnerability in their SDM Web interface.

FortiGuard Advisory #1 - FortiGuard published an advisory that describes an out-of-bounds write vulnerability (listed in CISA’s Known Exploit Exploits Catalog) in their FortiOS.

FortiGuard Advisory #2 - FortiGuard published an advisory that describes a lack of certificate validation vulnerability in their FortiOS.

FortiGuard Advisory #3 - FortiGuard published an advisory that describes a use of externally-controlled format string vulnerability.

FortiGuard Advisory #4 - FortiGuard published an advisory that discusses an uncontrolled resource consumption vulnerability (which is listed in CISA’s KEV) in their FortiOS and FortiProxy products.

GE Advisory - GE published an advisory that discusses a use of externally controlled format string vulnerability in their NetworkST4 and Remote Operations Offering.

Hitachi Advisory #1 - Hitachi published an advisory that discusses ten vulnerabilities in multiple Hitachi products.

Hitachi Advisory #2 - Hitachi published an advisory that discusses two vulnerabilities in their JP1 product.

HPE Advisory - HPE published an advisory that discusses 17 vulnerabilities in their Unified OSS Console Assurance Monitoring (UOCAM).  

Meinberg Advisory - Meinberg published an advisory that discusses 18 vulnerabilities in their LANTIME-Firmware.

Pilz Advisory - Pilz published an advisory that discusses six vulnerabilities.

SEL Advisory - SEL published an update notice for a new version of their SEL-5025 Secure Port Software which fixes two security issues.

Sharp Advisory - Sharp published an advisory that describes a path traversal vulnerability in multiple Sharp public display products.

VMware Advisory - VMware has published an advisory that describes five vulnerabilities in their VMware Aria Operations for Networks product.

WatchGuard Advisory #1 - WatchGuard published an advisory that describes a memory corruption vulnerability in their Endpoint products.

WatchGuard Advisory #2 - WatchGuard published an advisory that describes an out-of-bounds write vulnerability in their Endpoint products.

WatchGuard Advisory #3 - WatchGuard published an advisory that describes an arbitrary kernel read vulnerability in their Endpoint products.

WatchGuard Advisory #4 - WatchGuard published an advisory that discusses four Ivanti vulnerabilities.

Western Digital Advisory - Western Digital published an advisory that describes two vulnerabilities in their My Cloud, WD Cloud, and SanDisk ibi products.

Updates

HP Update - HP published an update for their UC Software advisory that was originally published on January 9th, 2024.

Exploits

Forta Exploit - James Horseman published an Metasploit module for a forced browsing vulnerability in the Forta GoAnywhere MFT.

Zyxel Exploit - Marco Ivaldi published an exploit for an improper input validation vulnerability in multiple Zyxel products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-2-3 - subscription required.

Saturday, November 25, 2023

Review – Public ICS Disclosures – Week of 11-18-23 – Part 2

For Part 2 we have seven more vendor disclosures from Mitsubishi, Philips, Phoenix Contact, Western Digital, WAGO (2), and Zyxel. There are also three updates from Hitachi Energy, HP, HPE. Finally, we have seven researcher reports about vulnerabilities in products from Thales (7).

Advisories

Mitsubishi Advisory - Mitsubishi published an advisory that describes two improper input validation vulnerabilities in their GX Works2 product.

Philips Advisory - Philips published an advisory that discusses the F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability that is listed on the CISA Known Exploited Vulnerability Catalog.

Phoenix Contact Advisory - Phoenix Contact published an advisory that discusses two vulnerabilities in products using the WIBU CodeMeter Runtime product.

Western Digital Advisory - Western Digital published an advisory that describes multiple uncontrolled search path element vulnerabilities (single CVE) in their SanDisk Security Installer for Windows product.

WAGO Advisory #1 - CERT-VDE published an advisory that describes an improper privilege management vulnerability in multiple WAGO products.

WAGO Advisory #2 - CERT-VDE published an advisory that describes an OS command injection vulnerability in WAGO managed switches.

Zyxel Advisory - Zyxel published an advisory that describes an out-of-bounds write vulnerability in their SecuExtender SSL VPN Client software.

Updates

Hitachi Energy Update - Hitachi Energy published an update for their Apache ActiveMQ advisory that was originally published on November 14th, 2023.

HP Update - HP published an update for their PROSet/Wireless WiFi and Killer™ WiFi advisory that was originally published on August 8th, 2023, and most recently updated on September 12th, 2023.

HPE Update - HPE published an update for their IceWall products advisory that was originally published on June 20th, 2023 and most recently updated on July 24th, 2023.

Researcher Reports

Thales Reports - Kaspersky published seven reports about individual vulnerabilities in the Thales Telit Cinterion products.

 

For more information on these disclosures, including links to 3rd party advisories and brief descriptions of changes in updates, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-11-cec - subscription required.

Saturday, August 12, 2023

Review – Public ICS Disclosures – Week of 8-5-23 – Part 1

This week we have 24 vendor disclosures from ABB, AUMA (2), Belden, Broadcom (3), Fujitsu, HP (6), HPE (2), Phoenix Contact (3), Rockwell, Sierra Wireless, Texas Instruments (2), Western Digital, and Zyxel.

Advisories

ABB Advisory - ABB published an advisory that describes two vulnerabilities in their Freelance AC 900F and AC 700F products.

AUMA Advisory #1 - CERT-VDE published an advisory that discusses a cross-site scripting vulnerability in their Master Station product.

AUMA Advisory #2 - CERT-VDE published an advisory that discusses an out-of-bounds write vulnerability in their Master Station product.

Belden Advisory - Belden published an advisory that discusses an out-of-bounds write vulnerability in their Hirschmann Owl product.

Broadcom Advisory #1 - Broadcom published an advisory that discusses a cleartext transmission of sensitive information vulnerability in their Brocade Fabric OS.

Broadcom Advisory #2 - Broadcom published an advisory that discusses a use after free vulnerability in their Brocade Fabric OS.

Broadcom Advisory #3 - Broadcom published an advisory that discusses an uncontrolled recursion vulnerability in their Brocade Fabric OS.

Fujitsu Advisory - Fujitsu published an advisory that discusses eleven vulnerabilities in multiple products.

HP Advisory #1 - HP published an advisory that discusses three vulnerabilities in multiple products.

HP Advisory #2 - HP published an advisory that discusses five vulnerabilities in multiple products.

HP Advisory #3 - HP published an advisory that discusses an insufficient input validation vulnerability in multiple HP products.

HP Advisory #4 - HP published an advisory that discusses a privilege escalation vulnerability in multiple HP products.

HP Advisory #5 - HP published an advisory that discusses a privilege escalation vulnerability in multiple HP products.

HP Advisory #6 - HP published an advisory that discusses six vulnerabilities in multiple HP products.

HPE Advisory #1 - HPE published an advisory that discusses the Inception vulnerability in their ProLiant AMD Servers.

HPE Advisory #2 - HPE published an advisory that discusses the Inception vulnerability in their ProLiant AMD Servers.

Phoenix Contact Advisory #1 - Phoenix Contact published an advisory that discusses eleven vulnerabilities in their PLCnext Engineer.

Phoenix Contact Advisory #2 - Phoenix Contact published an advisory that describes two vulnerabilities in their TC ROUTER and TC CLOUD CLIENT products.

Phoenix Contact Advisory #3 - Phoenix Contact published an advisory that describes 14 vulnerabilities in their WP 6xxx Web panels.

Rockwell Advisory - Rockwell published an advisory that described an incorrect calculation vulnerability in their Armor PowerFlex product.

Sierra Wireless Advisory - Sierra Wireless published an advisory that talks about recent cyberattacks on their AirLink Connection Manager products.

Texas Instruments Advisory #1 - Texas Instruments published an advisory that describes a PN reuse vulnerability in their WL18xx products.

Texas Instruments Advisory #2 - Texas Instruments published an advisory that describes an integer overflow vulnerability in their SimpleLink™ CC32XX SDK.

Western Digital Advisory - Western Digital published an advisory that describes 17 vulnerabilities in their My Cloud Home, My Cloud Home Duo and SanDisk ibi products.

Zyxel Advisory - Zyxel published an advisory that talks about a command injection vulnerability in their P660HN-T1A DSL CPE product (this product is end-of-life) which was originally corrected in 2017.

 

For more of the details about these advisories, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-258 - subscription required.

 
/* Use this with templates/template-twocol.html */