Showing posts with label WolfSSL. Show all posts
Showing posts with label WolfSSL. Show all posts

Sunday, November 5, 2023

Review – Public ICS Disclosure – Week of 10-28-23 – Part 2

For Part 2 we have six additional vendor disclosures from Philips, QNAP (3), VMware, and WolfSSL. There are 22 updates for previously made disclosures from Cisco (2), CODESYS (2), Hitachi Energy (13), HP (4), and Palo Alto Networks. We also have a researcher report for vulnerabilities for products from Phoenix Contact. Finally, we have an exploit for products from VMware.

Advisories

Philips Advisory - Philips published an advisory that discusses two vulnerabilities in their Vue PACS and Vue RIS/EI products.

QNAP Advisory #1 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, Multimedia Console, and Media Streaming add-on products.

QNAP Advisory #2 - QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero, and QuTScloud products.

QNAP Advisory #3 - QNAP published an advisory that describes a server side request forgery vulnerability in their QTS, QuTS hero, and QuTScloud products.

VMWare Advisory - VMWare published an advisory that describes an open redirect vulnerability in their VMware Workspace ONE UEM console.

WolfSSL Advisory - WolfSSL published an advisory that reports that the latest release of WolfSSL contains a fix for a Bleichenbacher style attack.

Updates

Cisco Update #1 - Cisco published an update for their IOS XE Software Web UI Feature advisory that was originally published on October 16th, 2023 and most recently updated on October 31st, 2023.

Cisco Update #2 - Cisco published an update for their HTTP/2 Rapid Reset Attack advisory that was originally published on October 16th, 2023 and most recently updated on October 31st, 2023.

CODESYS Update #1 - CODESYS published an update for their Development System V3 advisory that was originally published on July 20th, 2023 and most recently updated on August 3rd, 2023.

CODESYS Update #2 - CODESYS published an update for their Control V3 advisory that was originally published on July 20th, 2023, and most recently updated on August 3rd, 2023.

Hitachi Energy Update #1 - Hitachi Energy published an update for their Password in Memory Vulnerability advisory that was originally published on November 15, 2022.

Hitachi Energy Updates #2-12 - Hitachi Energy published updates for 12 advisories for the purpose of rebranding the advisories for “Hitachi/ABB Power Grids” to “Hitachi Energy”. No other changes were made.

HP Update #1 - HP published an update for their HP PC Hardware Diagnostics Windows advisory that was originally published on May 11th, 2023.

HP Update #2 - HP published an update for their HP PC BIOS September 2023 Security Updates for OpenSSL advisory that was originally published on September 5th, 2023.

HP Update #3 - HP published an update for their AMD Client UEFI Firmware August 2023 Security Update that was originally published on August 8th, 2023 and most recently updated on October 16th, 2023.

HP Update #4 - HP published an update for their AMD Client UEFI DXE Driver Memory Leaks advisory that was originally published on September 21st, 2023.

Palo Alto Networks Update - Palo Alto Networks published an update for their Impact of curl and libcurl Vulnerabilities advisory that was originally published on October 12th, 2023.

Researcher Reports

Phoenix Contact Report - Nozomi Networks published a report describing three vulnerabilities in the Phoenix Contact HMI product.

 

For more details about these disclosures including a brief summary of changes made in updates, links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-742 - subscription required.

Saturday, June 10, 2023

Review – Public ICS Disclosures – Week of 6-3-23

This week we have 10 vendor disclosures from Broadcom, Fuji Electric, GE Gas Power, Johnson Controls, Moxa, Philips, VMware, WolfSSL, and Zyxel (2). We also have a vendor update from HPE. There are 17 researcher reports for products from Suprema (4), Control ID (5), and Connected IO (8). Finally, we have 2 exploits for products from Zyxel and Delta Electronics.

Advisories

Broadcom Advisory - Broadcom published an advisory that discusses an SQL injection vulnerability in multiple products.

Fuji Advisory - JP-CERT published an advisory that describes the eight vulnerabilities in multiple Fuji server products.

GE Advisory - GE published an advisory that discusses four vulnerabilities in their Control Server Virtual HMIs and ThickClient HMIs.

Moxa Advisory - Moxa published an advisory that describes a weak cryptographic algorithm vulnerability in the CN2600 Series terminal servers

Philips Advisory - Philips published an advisory that discusses the MoveIT SQL injection vulnerability.

VMware Advisory - VMware published an advisory that describes three vulnerabilities in their VMware Aria Operations for Networks product.

WolfSSL Advisory - WolfSSL published a change log for a new version of their SSL product that reports two vulnerabilities in the previous version that are being fixed in the new release.

Zyxel Advisory #1 - Zyxel published an advisory that describes a buffer overflow vulnerability in their 4G LTE and 5G NR outdoor routers.

Zyxel Advisory #2 - Zyxel published an advisory that describes a privilege escalation vulnerability in their GS1900 series switches.

Updates

HPE Update - HPE published an update for their Aruba OpenSSL advisory that was originally published on February 15th, 2023 and most recently updated on May 22nd, 2023.

Researcher Reports

Suprmema Reports - Claroty published four reports about individual vulnerabilities in the Suprema BioStar security platform.

Control ID Reports - Claroty published five reports about individual vulnerabilities in the Control ID iDSecure product.

Connected IO Reports #1-4 - Claroty published four reports about individual vulnerabilities in the Control IO ER2000 edge router.

Connected IO Reports #5-8 - Claroty published four reports about individual vulnerabilities in the Control IO IDSecure product.

Exploits

Zyxel Exploit - Sf published a Metasploit module for a command injection vulnerability in the Zyxel firewalls.

Delta Exploit - Shelby Pace published a Metasploit module for a deserialization of untrusted data vulnerability in the Delta InfraSuite Device Master.

 

For more details about these disclosures, including links to researcher reports, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-f21 - subscription required.

 
/* Use this with templates/template-twocol.html */