Showing posts with label WithSecure. Show all posts
Showing posts with label WithSecure. Show all posts

Saturday, February 8, 2025

Review – Public ICS Disclosures – Week of 2-1-25

This week we have 19 vendor disclosures from ABB, Broadcom, Delta, HP (4), HPE (4), Meinberg, Moxa (2), Supermicro, WAGO (2), WithSecure, and Zyxel. We have two vendor updates from Broadcom and HP. Finally, there are also eleven researcher reports of vulnerabilities in products from ABB (8), Four-Faith (2), and Sensaphone.

Advisories

ABB Advisory - ABB published an advisory that describes a use of hard-coded credentials vulnerability (with publicly available exploit) in their ASPECT Energy Management System.

Broadcom Advisory - Broadcom published an advisory that discusses 25 Ivanti product vulnerabilities.

Delta Advisory - Delta published an advisory that describes a heap-based buffer overflow vulnerability in their CNCSoft-G2 product.

HP Advisory #1 - HP published an advisory that describes an improper handling of unexpected data type vulnerability in their LaserJet Pro Printers.

HP Advisory #2 - HP published an advisory that discusses two vulnerabilities in their Business Notebook products.

HP Advisory #3 - HP published an advisory that describes a path traversal vulnerability in their Poly Edge E devices.

HP Advisory #4 - HP published an advisory that describes an improper check for dropped privileges vulnerability in their Anyware Agent for Linux product.

HPE Advisory #1 - HPE published an advisory that discusses the BadRAM vulnerability in their HPE ProLiant Servers. This is a third-party (AMD) vulnerability.

HPE Advisory #2 - HPE published an advisory that discusses a protection measure failure vulnerability in their ProLiant DX Servers.

HPE Advisory #3 - HPE published an advisory that discusses an incorrect behavior order vulnerability in their ProLiant DX Servers.

HPE Advisory #4 - HPE published an advisory that discusses an improper verification of cryptographic signature vulnerability (with publicly available exploit) in their ProLiant AMD Servers.

Meinberg Advisory - Meinberg published an advisory that discusses four vulnerabilities in their LANTIME firmware.

Moxa Advisory #1 - Moxa published an advisory that describes an improper validation of specified type of input vulnerability in multiple Moxa switches.

Moxa Advisory #2 - Moxa published an advisory that describes an out-of-bounds write vulnerability in multiple Moxa switches.

Supermicro Advisory - Supermicro published an advisory that discusses an improper verification of cryptographic signature vulnerability (with publicly available exploit) in unnamed Supermicro products.

WAGO advisory #1 - CERT-VDE published an advisory that discusses an OS command injection vulnerability in multiple WAGO products.

WAGO Advisory #2 - CERT-VDE published an advisory that discusses an incorrect calculation of buffer size vulnerability in multiple WAGO products.

WithSecure Advisory - WithSecure published an advisory that describes a denial of service vulnerability in multiple WithSecure products.

Zyxel Advisory - Zyxel published an advisory that describes three vulnerabilities in multiple legacy DSL CPE models.

Updates

Broadcom Update - Broadcom published an update for their GridGain Security advisory that was originally published on October 16th, 2024.

HP Update - HP published an update for their AMD Graphics Driver advisory that was originally published on August 13th, 2024, and most recently updated on October 10th, 2024.

Researcher Report

ABB Reports - Zero Science published eight reports about vulnerabilities in the ABB Cylon FLXeon BACnet controller.

Four-Faith Report #1 - VulnCheck published a report about a use of hard-coded credentials vulnerability in the Four-Faith F3x36 router.

Four-Faith Report #2 - VulnCheck published a report about a hidden functionality vulnerability in the Four-Faith F3x36 router.

Sensaphone Report - Tyler Butler published a report that describes a stored cross-site scripting vulnerability (with a publicly available exploit) in the Sensaphone WEB600 Monitoring System.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-335 - subscription required.

Saturday, July 27, 2024

Review – Public ICS Disclosures – Week of 7-20-24

This week we have two CrowdStrike outage advisories. We also have 18 other vendor advisories for products from Broadcom, Draeger, Hitachi, HPE (4), Meinberg, National Instruments (7), WithSecure (2), and Zyxel. We have three vendor updates from Cisco (2) and HP. There is also a researcher report for vulnerabilities in products from Perkin Elmer. Finally, we have an exploit for products from Softing.

CrowdStrike Outage

GE Vernova published an advisory that discussed the impact on some of their Monitoring & Diagnostics products.

Philips published an advisory that provides a list of potentially affected products.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses ten vulnerabilities in the Azul Zulu component of their Brocade SANnav product.

Draeger Advisory - Draeger published an advisory that discusses a deserialization of untrusted data vulnerability (listed in the CISA Known Exploited Vulnerability Catalog).

Hitachi Advisory - Hitachi published an advisory that discusses 27 vulnerabilities in their Disk Array Systems.

HPE Advisory #1 - HPE published an advisory that describes three vulnerabilities in their Aruba EdgeConnect SD-WAN Orchestrator.

HPE Advisory #2 - HPE published an advisory that discusses 21 vulnerabilities (6 with known exploits) in their Unified OSS Console Assurance Monitoring (UOCAM) product.

HPE Advisory #3 - HPE published an advisory that discusses seven vulnerabilities (one with known exploit) in their Aruba EdgeConnect SD-WAN Gateways.

HPE Advisory #4 - HPE published an advisory that discusses an out-of-bounds write vulnerability in their ProLiant DL/ML/SY/XL and Alletra Servers.

Meinberg Advisory - Meinberg published an advisory that discusses ten vulnerabilities (2 with known exploits) in their Lantime product.

National Instruments Advisory #1 - National Instruments published an advisory that describes two missing authorization vulnerabilities in their VeriStand Gateway product.

National Instruments Advisory #2 - National Instruments published an advisory that describes two deserialization of untrusted data vulnerabilities in their VeriStand product.

National Instruments Advisory #3 - National Instruments published an advisory that describes a path traversal vulnerability in their VeriStand product.

National Instruments Advisory #4 - National Instruments published an advisory that describes a deserialization of untrusted data vulnerability in their VeriStand Project File product.

National Instruments Advisory #5 - National Instruments published an advisory that describes an integer overflow or wraparound vulnerability in their TDMS Files in LabVIEW.

National Instruments Advisory #6 - National Instruments published an advisory that describes an incorrect default permissions vulnerability in their SystemLink Redis Service.

National Instruments Advisory #7 - National Instruments published an advisory that describes an out-of-date component with multiple vulnerabilities vulnerability in their SystemLink Server.

WithSecure Advisory #1 - WithSecure published an advisory that describes a denial of service vulnerability in their WithSecure Mac antivirus software.

WithSecure Advisory #2 - WithSecure published an advisory that describes a privilege escalation vulnerability in their WithSecure Mac Products.

Zyxel Advisory - Zyxel published an advisory that describes an improper privilege management vulnerability in their Zyxel AP products.

Updates

Cisco Update #1 - Cisco published an update for their Blast-Radius advisory that was originally published on July 10th, and most recently updated on July 19th, 2024.

Cisco Update #2 - Cisco published an update for their regreSSHion advisory that was originally published on July 2nd, 2024, and most recently updated on July 19th, 2024.

HP Update - HP published an update for their Display Control Software advisory that was originally published on July 15th, 2024.

Researcher Reports

Perkin Elmer Report - Cyber Danube published a report that describes three vulnerabilities in the Perkin Elmer ProcessPlus measurement software.

Exploits

Softing Exploit - Mr me published a Metasploit module for two vulnerabilities in the Softing Secure Integration Server.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-d58 - subscription required.

Saturday, May 25, 2024

Review – Public ICS Disclosures – Week of 5-18-24

This week we have 13 vendor disclosures from Broadcom (3), Cisco, Fujitsu, HP (2), HPE, Philips, QNAP, WAGO (2), WithSecure, and Zyxel. We also have two vendor updates from Broadcom and HPE. Finally, we have ten researcher reports for products from FortiGuard, Honeywell, Mitsubishi, Siemens, TP-Link (5), and TVT.

Advisories

Broadcom Advisory #1 - Broadcom published an advisory that discusses a deserialization of untrusted data vulnerability in their Brocade Fabric OS, Brocade SANnav, and Brocade Support Link products.

Broadcom Advisory #2 - Broadcom published an advisory that discusses six inadequate access control vulnerabilities in their Brocade SANnav product.

Broadcom Advisory #3 - Broadcom published an advisory that describes a missing authentication for critical resource vulnerability in their Brocade SANnav product.

Cisco Advisory - Cisco published an advisory that describes an authentication bypass by spoofing vulnerability in their Snort 3 HTTP Intrusion Prevention System.

Fujitsu Advisory - Fujitsu published an advisory that discusses four vulnerabilities in multiple Fujitsu products.

HP Advisory #1 - HP published an advisory that describes a cross-site scripting vulnerability in their LaserJet Pro devices.

HP Advisory #2 - HP published an advisory that describes an SMTP server information disclosure vulnerability in their Laser Jet Pro printers.

NOTE: This link to this advisory is currently leading to a blank page.

HPE Advisories - HPE published 46 Critical Product Security Vulnerability Alerts. See this post for background information on these products.

Philips Advisory - Philips published an advisory that discusses the HPE authorization bypass through user-controlled key vulnerability.

QNAP Advisory - QNAP published an advisory that describes five vulnerabilities in their QTS and QuTS hero products.

WAGO Advisory #1 - CERT-VDE published an advisory that discusses 17 vulnerabilities in multiple WAGO products.

WAGO Advisory #2 - CERT-VDE published an advisory that discusses two vulnerabilities in WAGO Navigator.

WithSecure Advisory - WithSecure published an advisory that describes a link following vulnerability in their Windows endpoint product.

Zyxel Advisory - Zyxel published an advisory that describes two classic buffer overflow vulnerabilities in their 5G NR/4G LTE CPE, DSL/Ethernet CPE, fiber ONT, and WiFi extender.

Updates

Broadcom Update - Broadcom published an update for their remote code execution advisory that was originally published on April 1st, 2024.

HPE Update - HPE published an update for their Aruba ArubaOS advisory that was originally published on April 30th, 2024.

Researcher Reports

FortiGuard Report - Horizon3 published a report describing an OS command injection vulnerability in the Fortinet FortiSIEM product.

Honeywell Report - Claroty published a report describing two vulnerabilities in the Honeywell ControlEdge Virtual Unit Operations Center (UOC).

Mitsubishi Report - Positive Technologies published a report describing five vulnerabilities in the Mitsubishi MELSEC System Q and MELSEC System L series PLC processor modules.

Siemens Report - SEC Consult published a report describing an exposed serial shell vulnerability on multiple Siemens PLCs.

TP-Link Reports - ZDI published five reports of vulnerabilities in the TP-Link TP-Link Omada ER605 PPTP VPN.

TVT Report - SSD-Disclosure published a report that describes an exposure of sensitive information vulnerability in the TVT NVMS9000 surveillance management system.

 

For more information on these disclosures, including links to 3rd party advisories and researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-329 - subscription required.

 
/* Use this with templates/template-twocol.html */