This week we have four vendor disclosures related to the QNX RTOS vulnerability from Draeger, GE Healthcare, Medtronic, and Schneider Electric. We also have two vendor disclosures related to the PrintNightmare vulnerabilities from BD, Boston Scientific. We also have eight other vendor disclosures from BD, PEPPERL+FUCHS (2), Hitachi ABB Power Grids, Johnson Controls, Moxa, Siemens, and VMware. Finally, we have two researcher reports for vulnerabilities in products from Altus Sistemas de Automacao, and NetModule.
QNX Advisories
Draeger published an advisory discussing the QNX RTOS vulnerability. They announced that none of their products are affected.
GE Healthcare published an advisory discussing the QNX RTOS vulnerability. They announced that none of their products utilizing the QNX RTOS are affected by the vulnerability.
Medtronic published an advisory discussing the QNX RTOS vulnerability. They announced that none of their products are affected.
Schneider published an advisory discussing the QNX RTOS vulnerability. They announced that they are continuing to monitor the situation.
PrintNightmare Advisories
BD published an advisory discussing the PrintNightmare vulnerabilities. They provide a list of affected products and are continuing to evaluate the Microsoft® patch.
Boston Scientific published an advisory discussing the PrintNightmare vulnerabilities. They announced that their LabSystem PRO EP Recording System is affected by the vulnerabilities. They do not currently recommend applying the Microsoft patch and continue to work on mitigation measures.
BD Advisory
BD published an advisory discussing the URGENT/11 vulnerabilities. They provide a list of affected products and provide generic mitigation measures while developing a fix for the vulnerabilities.
PEPPERL+FUCHS Advisories
CERT-VDE published an advisory describing 19 vulnerabilities in the PEPPERL+FUCHS WirelessHART-Gateway products. Some of these are third party (jQuery and TLS) vulnerabilities. PEPPERL+FUCHS provides generic mitigation measures.
The 19 reported vulnerabilities are:
Path traversal - CVE-2021-33555,
Cross-site scripting (9) - CVE-2020-11023 (exploit), CVE-2020-11022, (exploit), CVE-2020-7656 (exploit), CVE-2019-11358, CVE-2015-9251, CVE-2014-6071, CVE-2012-6708 (exploit), CVE-2011-4969 (exploit), and CVE-2021-34562,
Uncontrolled resource consumption - CVE-2016-10707 (exploit),
Exposure of sensitive information to an unauthorized actor - CVE-2007-2379,
HTTP request smuggling - CVE-2021-34559,
Information exposure - CVE-2021-34560,
Reliance on reverse DNS resolution for security-critical action - CVE-2021-34561,
Sensitive cookie without ‘HTTPOnly’ flag - CVE-2021-34563,
Cleartext storage of sensitive information in a cookie - CVE-2021-34564,
Cryptographic issues - CVE-2013-0169, and
Use of hard-coded credentials - CVE-2021-34565
CERT-VDE published an advisory discussing the Ripple20 vulnerabilities in the PEPPERL+FUCHS VDM100-Distance Ethernet-IP sensors. PEPPERL+FUCHS provides generic mitigation measures.
Hitachi ABB Advisory
Hitachi ABB published an advisory discussing the BadAlloc vulnerabilities. They have identified that their Modular Switchgear Monitoring System MSM is an affected product. Hitachi ABB provides generic workarounds to mitigate the vulnerabilities.
Johnson Controls Advisory
Johnson Controls published an advisory discussing the impact on the out-of-support status of the Window CE OS on their Kantech KT-1 door controller. They recommend updating to their newer version that runs on a current Linux OS.
Moxa Advisory
Moxa published an advisory describing four vulnerabilities in their EDR-810 Series secure router. The vulnerabilities were reported by Danny Rigby and Alan Chang from Modux. Moxa has a security patch for three of the four vulnerabilities.
The four reported vulnerabilities are:
Use of a broken or risky cryptography algorithm,
Stack-based buffer overflow,
Improper neutralization of special elements in an OS command, and
Use of a hard-coded cryptographic key
Siemens Advisory
Siemens published an out-of-zone advisory describing an external control of system or configuration setting vulnerability in their SINEMA Remote Connect Client. The vulnerability is reported by Amir Preminger from Claroty. Siemens has a firmware update that mitigates the vulnerability. There is no indication that Preminger has been provided an opportunity to verify the efficacy of the fix.
VMware Advisory
VMware published an advisory describing a denial-of-service vulnerability in their Workspace ONE UEM console. VMware has new versions that mitigate the vulenrabilty.
Altus Sistemas de Automacao Report
SEC Consult published a report describing three vulnerabilities in PLC products from Altus Sistemas de Automacao. This was a coordinated disclosure. The report contains proof-of-concept code. Altus has new versions that mitigate three of the vulnerabilities.
The four reported vulnerabilities are:
Semi-blind command injection via parameter injection - CVE-2021-39244,
Cross-site request forgery - CVE-2021-39243,
Hard-coded credentials for CGI endpoint - CVE-2021-39245, and
Outdated and vulnerable software components (no fix)
NetModule Report
SEC Consult published a report describing three vulnerabilities in the NetModule router software product. This was a coordinate disclosure. The repot contains proof-of-concept code. NetModule has new firmware versions that mitigate the vulnerabilities.
The three reported vulnerabilities are:
Insecure password handling - CVE-2021-39289,
Limited session fixation via cookie - CVE-2021-39290, and
Insecure feature (web CLI) - CVE-2021-39291