Showing posts with label strongSwan. Show all posts
Showing posts with label strongSwan. Show all posts

Sunday, May 17, 2026

Review - Public ICS Disclosures – Week of 5-9-26 – Part 2

 For Part 2 we have six additional vendor disclosures from Dell, Supermicro (3), VMware, and Westermo. There are 24 bulk vendor updates for products from ELECOM (6), Schneider (7), and Siemens (11). Finally, we have two exploits for products from OpenPLC and strongSwan. 

Advisories  

Dell Advisory - Dell published an advisory that discusses three vulnerabilities (all listed in CISA’s KEV catalog) in their ThinOS products. 

Supermicro Advisory #1 - Supermicro published an advisory that discusses a microarchitectural predictor vulnerability in multiple Supermicro products. 

Supermicro Advisory #2 - Supermicro published an advisory that discusses three vulnerabilities in multiple Supermicro products. 

Supermicro Advisory #3 - Supermicro published an advisory that discusses an improper initialization vulnerability in multiple Supermicro products. 

VMware Advisory - Broadcom published an advisory that describes a TOCTOU race condition vulnerability in the VMware Fusion product. 

Westermo Advisory Westermo published an advisory that discusses an out-of-bounds read vulnerability in their Merlin and Virtual Access GW Series OSPF products. 

Updates  

Bulk Vendor Updates – ELECOM (6) 

Bulk Vendor Updates – Schneider (7) 

Bulk Vendor Updates – Siemens (11) 

Exploits  

OpenPLC Exploit - Unicorn-hyh published an exploit for a path traversal vulnerability in OpenPLC-v3. 

StrongSwan Exploit - Indoushka published a Metasploit module for an integer underflow vulnerability in the strongSwan EAP-TTLS implementation. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-6f8 - subscription required. 

Saturday, March 4, 2023

Review - Public ICS Disclosure – Week of 3-3-23

This week we have 25 vendor disclosures from ABB (2), Aruba Networks, BaiCells, Bosch, B&R (2), Hitachi Energy, HPE (7), JTEKT Electronics, Milestone, Reillo, StrongSwan, Tanzu (2), VMware, WAGO, Western Digital, and Wireshark. We also have three vendor updates from HPE (2) and Mitsubishi. Finally we have ten researcher reports for products from Osprey (9) and DJI drones.

Vendor Advisories

ABB Advisory #1 - ABB published an advisory that discusses an improper resource shutdown or release vulnerability in ABB AC 800PEC and AC 800PEC-based products.

ABB Advisory #2 - ABB published an advisory that describes an improper authentication vulnerability in their S+ Operations products.

Aruba Advisory - Aruba published an advisory that describes 33 vulnerabilities in their ArubaOS product.

BaiCells Advisory - BaiCells published an advisory that describes a command injection vulnerability in their EG7035-M11 CPE Series products.

Bosch Advisory - Bosch published an advisory that discusses an allocation of resources without limit or throttling vulnerability in their FL MGUARD and TC MGUARD routers.

B&R Advisory #1 - B&R published an advisory that describes five vulnerabilities in their APROL database.

B&R Advisory #2 - B&R published an advisory that discusses five vulnerabilities in their Mobile Panel and Power Panel products.

Hitachi Energy Advisory - Hitachi published an advisory that describes an update signature validation vulnerability in their Relion® 670, 650 and SAM600-IO Series Products.

HPE Advisory #1 - HPE published an advisory that discusses four improper access control vulnerabilities in their Moonshot/Edgeline Servers.

HPE Advisory #2 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #3 - HPE published an advisory that discusses a privilege escalation vulnerability in their Apollo, XL Servers.

HPE Advisory #4 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #5 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #6 - HPE published an advisory that discusses an information disclosure vulnerability in their Edgeline Servers.

HPE Advisory #7 - HPE published an advisory that discusses a privilege escalation vulnerability in their Edgeline Servers.

HPE Advisory #8 - HPE published an advisory that discusses two vulnerabilities in their ProLiant DL/ML/Microserver Servers.

JTEKT Advisory - JP Cert published an advisory that describes three vulnerabilities in the JTEKT Kostac PLC Programming Software.

Milestone Advisory - Milestone published an advisory that announces that their online services no longer support TLS v1.0 and TLS v1.1 protocols.

Riello Advisory - Incibe CERT published an advisory that describes three vulnerabilities in the Riello UPS NetMan 204.

StrongSwan Advisory - StrongSwan published an advisory that describes a certificate verification vulnerability in StrongSwan.

Tanzu Advisory #1 - Tanzu published an advisory that discusses three vulnerabilities in multiple Tanzu products.

Tanzu Advisory #2 - Tanzu published an advisory that discusses two vulnerabilities in multiple Tanzu products.

VMware Advisory - VMware published an advisory that describes a passcode bypass vulnerability in their Workspace ONE Content product.

WAGO Advisory - CERT VDE published an advisory that describes four vulnerabilities in multiple WAGO products.

Western Digital Advisory - Western Digital published an advisory that the latest version of their SanDisk PrivateAccess no longer supports “insecure TLS 1.0 and TLS 1.1 protocols”.

Wireshark Advisory - Wireshark published an advisory that describes a packet injection vulnerability in their ISO 15765 and ISO 10681 dissectors.

Vendor Updates

HPE Update #1 - HPE published an update for their Intel 500 Series Ethernet Controllers advisory that was originally published on February 14th, 2023.

HPE Update #2 - HPE published an update for their ProLiant DL/ML/Microserver Servers that was originally published on February 14th, 2023.

Mitsubishi Update - Mitsubishi published an update for their WEB Server Function on MELSEC Series that was originally published on January 17th, 2023 and most recently updated on January 26th, 2023.

NOTE: NCCIC-ICS has not updated their advisory (ICSA-23-017-02) for this new information.

Researcher Reports

Osprey Report #1 - Zero Science published a report that describes a security bypass vulnerability in the Osprey Pump Controller.

Osprey Report #2 - Zero Science published a report that describes an information disclosure vulnerability in the Osprey Pump Controller.

Osprey Report #3 - Zero Science published a report that describes an administrator backdoor vulnerability in the Osprey Pump Controller.

Osprey Report #4 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #5 - Zero Science published a report that describes a command injection vulnerability in the Osprey Pump Controller.

Osprey Report #6 - Zero Science published a report that describes a reflected cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #7 - Zero Science published a report that describes an authentication bypass vulnerability in the Osprey Pump Controller.

Osprey Report #8 - Zero Science published a report that describes a cross-site scripting vulnerability in the Osprey Pump Controller.

Osprey Report #9 - Zero Science published a report that describes a remote code execution vulnerability in the Osprey Pump Controller.

DJI Drones Report - Nico Schiller, et. al. from the Ruhr University Bochum published a report that describes multiple security vulnerabilities in the control system for DJI consumer drones.

 

For more details about these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-3-3 - subscription require.

Saturday, October 8, 2022

Review – Public ICS Disclosure – Week of 10-1-22

This week we have six vendor disclosures from Bentley (3), Hitachi, strongSwan, VMware. We also have seven vendor updates from CODESYS. Finally, we have two researcher reports with exploits for products from ZKSecurity.

Bentley Advisory #1 - Bentley published an advisory that describes an out-of-bounds read vulnerability in their MicroStation and MicroStation-based applications.

Bentley Advisory #2 - Bentley published an advisory that describes two vulnerabilities in their MicroStation and MicroStation-based applications.

Bentley Advisory #3 - Bentley published an advisory that describes two vulnerabilities in their MicroStation and MicroStation-based applications.

Hitachi Advisory - Hitachi published an advisory that discusses 39 vulnerabilities in their Disk Array Systems.

StrongSwan Advisory - StrongSwan published an advisory describing a trust chain vulnerability in their strongSwan product.

VMware Advisory - VMware published an advisory that describes two vulnerabilities in their VMware ESXi and vCenter Server products.

CODESYS Update #1 - CODESYS published an update for their CODESYS V3 Visualization advisory that was originally published on June 3rd, 2022.

CODESYS Update #2 - CODESYS published an update for their CODESYS V2 password transport advisory that was originally published on June 9th, 2022 and most recently updated on June 23rd, 2022.

CODESYS Update #3 - CODESYS published an update for their CODESYS OPC DA Server V3 advisory that was originally published on May 19th, 2022 and most recently updated on June 3rd, 2022.

CODESYS Update #4 - CODESYS published an update for their CODESYS communication server advisory that was originally published on May 19th, and most recently updated on June 3rd, 2022.

CODESYS Update #5 - CODESYS published an update for their CODESYS Control V3 configuration file access advisory that was originally published on March 24th, 2022, and most recently updated on June 30th, 2022.

CODESYS Update #6 - CODESYS published an update for their CODESYS Git advisory that was originally published on November 30th, 2021.

CODESYS Update #7 - CODESYS published an update for their CODESYS V2 web server that was originally published on October 25, 2021 and most recently updated on November 8th, 2022.

ZKSecurity Report #1 - Stolabs published a report that describes an SQL injection vulnerability in the ZKSecurity Bio product.

ZKSecurity Report #2 - Caio B published a report that describes an access control vulnerability in the ZKSecurity Bio product.

 

For more details about these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosure-week-of-10-0f6 - subscription required.


 
/* Use this with templates/template-twocol.html */