Showing posts with label Wiesemann & Theis. Show all posts
Showing posts with label Wiesemann & Theis. Show all posts

Saturday, August 23, 2025

Review – Public ICS Disclosures – Week of 8-16-25

This is a moderately busy disclosure week. We have bulk disclosures from HPE (7). This week we have five additional vendor disclosures from Delta Electronics, Honeywell, HP, SMA, and Weissmann & Theis. We have bulk updates from Dell (5). We have three vendor updates from HPE and Siemens (2). There is also a researcher report for a vulnerability in a product from Ilevia. Finally, we have an exploit for products from Lantronix.

Bulk Disclosures

HPE published 7 disclosures.

Advisories

Delta Advisory - Delta published an advisory that describes four cross-site scripting vulnerabilities in their DIAEnergie products.

Honeywell Advisory - Honeywell published an end-of-life notice for their Select 60 Series cameras.

HP Advisory - HP published an advisory that discusses two vulnerabilities in their Security Manager product.

SMA Advisory - CERT-VDE published an advisory that describes an exposure of private personal data to an unauthorized actor vulnerability in the SMA ennexos.sunnyportal.com.

Wiesemann Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the Wiesemann Motherbox 3 product.

Bulk Updates

Dell published five updates for their Wyse product line.

Updates

HPE Updates - HPE published an update for their ProLiant DL/ML/XL advisory that was originally published on August 12th, 2025.

Siemens Update #1 - Siemens published an update for their Desigo CC Product Family advisory that was originally published on August 14th, 2025.

Siemens Update #2 - Siemens published an update for their e OPC UA Implementations advisory that was originally published on September 12th, 2023, and most recently updated on January 14th, 2025.

Researcher Reports

Ilevia Report - Zero Science published a report describing a server-side logging vulnerability (with publicly available exploit) in the Ilevia EVE X1 Server.

Exploits

Lantronix Exploit - Byte Reaper published an exploit for an improper restriction of XML external entity reference vulnerability in the Lantronix Provisioning Manager.


For more information on these disclosures, including links to 3rd party advisories, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-8-86f - subscription required.


Saturday, March 2, 2024

Review – Public ICS Disclosures – Week of 2-26-24

This week we have 12 vendor disclosures from Aruba Networks, CODESYS, Dell, Festo, Hikvision, Hitachi Energy, HP, Moxa, Philips, SMA, Wiesemann & Theis, and VMware. There are four vendor updates from Hitachi Energy. There is a researcher report for a vulnerability in products from Qognify. Finally, we have three exploits for products from Automatic Systems (2), and Saflok.

Advisories

Aruba Advisory - Aruba published an advisory that describes ten vulnerabilities in their ClearPass Policy Manager product.

CODESYS Advisory - CODESYS published an advisory that describes an OS command injection vulnerability in their Control V3 on Linux and QNX operating systems product.

Dell Advisory - Dell published an advisory that discusses TPM Interposer BitLocker research.

Festo Advisory - CERT-VDE published an advisory that discusses 140 vulnerabilities in the Festo MES PCs.

Hikvision Advisory - Hikvision published an advisory that describes two improper server-side validation vulnerabilities in their HikCentral Professional product.

Hitachi Energy Advisory - Hitachi Energy published an advisory that discusses the Terrapin-Attack vulnerability.

HP Advisory - HP published an advisory that discusses 133 vulnerabilities in their ThinPro product. These are third-party vulnerabilities.

Moxa Advisory - Moxa published an advisory that describes a confused deputy vulnerability in their EDS-4000/G4000 Series products.

Philips Advisory - Philips published an advisory that discusses a use after free vulnerability in their EarlyVue VS30.

SMA Advisory - Incibe-CERT published an advisory that describes two vulnerabilities in the SMA Cluster Controller and Sunny Webbox products.

Wiesemann & Theis Advisory - CERT-VDE published an advisory that describes an unquoted search path vulnerability in multiple Wieseman & Theis products.

VMware Advisory - VMware published an advisory that describes an out-of-bounds read vulnerability in their Workstation Pro and Fusion products.

Updates

Hitachi Energy Update #1 - Hitachi Energy published an update for their RTU500 advisory that was originally published on December 19th, 2023.

Hitachi Energy Update #2 - Hitachi Energy published an update for their RTU500 advisory that was originally published on November 28th, 2023 and most recently updated on December 13th, 2023.

Hitachi Energy Update #3 - Hitachi Energy published an update for their OpenSSL advisory that was originally published on April 25th, 2023.

Hitachi Energy Update #4 - Hitachi Energy published an update for their IEC 61850 MMS-Server advisory that was originally published on February 14th, 2023.

Researcher Reports

Qognify Report - SEC Consult published a report that describes an uncontrolled search path element in the Qognify VMS Client Viewer.

Exploits

Automatic Systems Exploit #1 - Marcin Kozlowski published an exploit for a path traversal vulnerability in the Automatic-Systems SOC FL9600 FastLine.

Automatic Systems Exploit #2 - Marcin Kozlowski published an exploit for a use of hard-coded credentials vulnerability in the Automatic-Systems SOC FL9600 FastLine product.

Saflok Exploit - A51199deefa2c2520cea24f746d899ce published an exploit for a key derivativation vulnerability in the Saflok System 6000.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-584 - subscription required.

Sunday, December 18, 2022

Review – Public ICS Disclosures – Week of 12-10-22 – Part 2

For part 2 we have twelve additional vendor disclosures from Rockwell Automation (3), Schneider (2), Sick, VMware (4), Weidmueller, and Wiesemann & Theis. We also have seven vender updates from CODESYS (3), Dell, HPE, Mitsubishi, and Omron. Finally, we have one researcher report for products from VMware.

Vendor Disclosures

Rockwell Advisory #1 - Rockwell published an advisory that describes a denial of service vulnerability in their MicroLogix 1100 & 1400 Product Web Server application.

Rockwell Advisory #2 - Rockwell published an advisory that describes a cross-site scripting vulnerability in their MicroLogix 1100 & 1400 Web Server application.

Rockwell Advisory #3 - Rockwell published an advisory that describes a denial of service vulnerability in their GuardLogix and ControlLogix controllers.

Schneider Advisory #1 - Schneider published an advisory that describes an improper authorization vulnerability in their EcoStruxure Power Commission.

Schneider Advisory #2 - Schneider published an advisory that discusses an out-of-bounds write vulnerability in their Saitel DR RTU (Remote Terminal Unit).

Sick Advisory - Sick published an advisory that describes four vulnerabilities in the n SICK RFU6xx RADIO FREQUEN. SENSOR 1.

VMware Advisory #1 - VMware published an advisory that describes two vulnerabilities in their vRealize Network Insight (vRNI) product.

VMware Advisory #2 - VMware published an advisory that describes two vulnerabilities in their Workspace ONE Access and Identity Manager.

VMware Advisory #3 - VMware published an advisory that describes a heap-based write vulnerability in their ESXi, Workstation, and Fusion products.

VMware Advisory #4 - VMware published an advisory that describes two vulnerabilities in their vRealize Operations product.

Weidmueller Advisory - CERT-VDE published an advisory that describes a JavaScript injection vulnerability in the Weidmueller XML editing system SCHEMA ST4 online help.

Wiesemann & Theis Advisory - CERT-VDE published an advisory that describes an authentication bypass by spoofing vulnerability in multiple Wiesemann & Theis products.

Vendor Updates

CODESYS Update #1 - CODESYS published an update for their Control V3 communication server advisory that was originally published on November 22nd, 2022.

CODESYS Update #2 - CODESYS published an update for their V3 boot application advisory that was originally published on November 23rd, 2022.

CODESYS Update #3 - CODESYS published an update for their V2 password transport advisory that was originally published on June 9th, 2022 and most recently updated on October 6th, 2022.

CODESYS Update #4 - CODESYS published an update for their V2 and V3 runtime systems advisory that was originally published on March 22nd, 2018 and most recently updated on July 9th, 2018.

Dell Update - Dell published an update for their Log4Shell advisory.

HPE Update - HPE published an update for their NonStop advisory that was originally published on July 18th, 2022.

Mitsubishi Update - Mitsubishi published an update for their GENESIS64TM and MC Works64 advisory that that was originally published on July 19th, 2022 and most recently updated on September 30th, 2022.

Omron Update - JP-CERT published an update for their OMRON CX-Programmer advisory that was originally published on November 25th, 2022.

Researcher Report

VMware Report - CISCO Talos published a report describing a denial-of-service vulnerability in the VMware vCenter Server Content Library.

 

For additional information on these disclosures, including links to third-party advisories, exploits, and brief summary of changes made, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-12-720 - subscription required.


 
/* Use this with templates/template-twocol.html */