This week we have eleven vendor disclosures from Aruba Networks, Carestream, CODESYS, Hitachi-ABB Power Grids, Philips, PulseSecure (2), SonicWall (2), and VMware (2). We have an updated disclosure from HMS. There are ten researcher reports for products from Advantech (4), Rockwell (5), and Schneider. Finally, we have three exploits for products from VMware, and Aruba (2).
Aruba Advisory
Aruba published an advisory describing four vulnerabilities in their AOS-CX Devices. The vulnerabilities were reported by K. Man et al (SAD DNS), and Erik de Jong. Aruba has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The four reported vulnerabilities are:
SAD DNS - CVE-2020-25705,
Security bypass - CVE-2021-29149,
Path-relative stylesheet import - CVE-2021-29148, and
Code execution via external storage - CVE-2021-29143
NOTE: Interestingly, Aruba is using the CVE for an NCCIC-ICS advisory for a Siemens reported version of the SAD DNS vulnerability.
Carestream Advisory
Carestream published an advisory discussing the PrintNightmare vulnerabilities. The advisory provides a list of affected and unaffected products as well as mitigation measures for affected products.
CODESYS Advisory
CODESYS published an advisory describing six vulnerabilities in their V2 web servers. The vulnerabilities were reported by Vyacheslav Moskvin, Sergey Fedonin and Anton Dorfman of Positive
Technologies. CODESYS has an update available that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The six reported vulnerabilities are:
Stack-based buffer overflow - CVE-2021-30189,
Improper access control - CVE-2021-30190,
Buffer copy without checking size of input - CVE-2021-30191,
Improperly implemented security check - CVE-2021-30192,
Out-of-bounds write - CVE-2021-30193, and
Out-of-bounds read - CVE-2021-30194
Hitachi-ABB Advisory
Hitachi-ABB published an advisory describing a password autocomplete vulnerability in their eSOMS web application. The vulnerability was privately reported to Hitachi-ABB. Hitachi-ABB had a new version that mitigates the vulnerability.
Philips Advisory
Philips published an advisory discussing the latest SolarWinds vulnerability. Philips has not currently identified any vulnerable products.
PulseSecure Advisories
PulseSecure published an advisory discussing three OpenSSL vulnerabilities. PulseSecure is currently reviewing their products to see if they are affected.
The three OpenSSL vulnerabilities are:
Incorrect SSLv2 rollback protection - CVE-2021-23839,
Null pointer dereference - CVE-2021-23841, and
Integer overflow - CVE-2021-23840
PulseSecure published an advisory discussing two OpenSSL vulnerabilities. PulseSecure is currently reviewing their products to see if they are affected.
The two OpenSSL vulnerabilities are:
CA certificate check bypass - CVE-2021-3450, and
Null pointer dereference - CVE-2021-3449
SonicWall Advisories
SonicWall published an advisory discussing two OpenSSL vulnerabilities. SonicWall has new versions that mitigate the vulnerabilities.
The two OpenSSL vulnerabilities are:
CA certificate check bypass - CVE-2021-3450, and
Null pointer dereference - CVE-2021-3449
SonicWall published an advisory describing an SQL injection vulnerability in their end-of-life Secure Remote Access (SRA) products. The vulnerability was reported by CrowdStrike. A newer version mitigated the vulnerability.
VMware Advisories
VMware published an advisory describing two vulnerabilities in their ESXi product. The vulnerability was reported by Douglas Everson of Voya Financial. VMware has new versions that mitigate the vulnerabilities. There is no indication that Everson was provided with an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Improper authentication - CVE-2021-21994, and
Denial of service - CVE-2021-21995
VMware published an advisory describing a DLL hijacking vulnerability in their ThinApp product. The vulnerability was reported by Hou JingYi of Qihoo 360. VMware has new versions that mitigate the vulnerability. There is no indication that Hou has been provided an opportunity to verify the efficacy of the fix.
HMS Update
HMS published an update for their advisory that was originally published on July 7th, 2021. The new information include raising the CVSS base score to 6.1.
Advantech Reports
Talos published four vulnerability reports for six vulnerabilities in the Advantech R-SeeNet product. These were coordinated through CISA’s NCCIC-ICS, but Talos reports no response. The six reported vulnerabilities are:
Cross-site scripting - CVE-2021-21799, CVE-2021-21801, CVE-2021-21802, CVE-2021-21803, and CVE-2021-21800, and
OS command injection - CVE-2021-21805.
Rockwell Reports
Kaspersky published five reports on vulnerabilities in the Rockwell Automation ISaGRAF Runtime product. Rockwell and NCCIC-ICS had previously reported these vulnerabilities publicly on June 8th, 2021. The five Kaspersky reports cover the following vulnerabilities:
Uncontrolled search path element - CVE-2020-25182,
Use of hard-coded cryptographic key - CVE-2020-25180,
Clear-text storage of sensitive information - CVE-2020-25184,
Relative path traversal - CVE-2020-25176, and
Clear-text transmission of sensitive information - CVE-2020-25178
Schneider Report
Tenable published a report describing an authentication bypass vulnerability in the Schneider Modicon M340/M580 PLC. This vulnerability was previously reported by Schneider and NCCIC-ICS. Tenable provides proof-of-concept code in a linked article. The Tenable report includes an interesting disclosure timeline discussion.
VMware Exploit
Wvu published a Metasploit module for an input validation vulnerability in the VMware vCenter Server. The vulnerability was previously reported by VMware.
Aruba Exploits
Aleph Security published an exploit for eight vulnerabilities in the Aruba Instant (IAP) product. The vulnerabilities were previously reported by Aruba.
GR33NH4T published an exploit for an arbitrary file write vulnerability in the Aruba Instant (IAP) product. The vulnerability was previously reported by VMware.