This week we have 24 vendor disclosures from Festo, Hitachi (6), Hitachi Energy (3), Honeywell, Pilz, and QNAP (12).
Festo Advisory
CERT-VDE published an advisory that discusses 16 vulnerabilities in the multiple Festo products. These are third-party (CODESYS) vulnerabilities. Festo provides generic mitigation measures pending release of a correcting update in third quarter of 2024.
Hitachi Advisories
Hitachi published an advisory that discusses seven undescribed vulnerabilities in their Cosminexus Developer's Kit for Java(TM) and Hitachi Developer's Kit for Java. These are third-party (Oracle) vulnerabilities. No fixes are currently available.
Hitachi published an advisory that discusses 11 vulnerabilities in their Ops Center Analyzer. These are third-party (Node.js) vulnerabilities. No fixes are currently available.
The eleven reported vulnerabilities are:
OS command injection - CVE-2022-43548,
Incorrect authorization - CVE-2023-23918,
Cryptographic issues - CVE-2023-23919 (exploit),
Untrusted search path - CVE-2023-23920,
Injection - CVE-2023-23936 (exploit),
Inefficient regular expression complexity - CVE-2023-24807,
Undescribed (3) - CVE-2023-30581, CVE-2023-30585, and CVE-2023-30588,
HTTP request smuggling - CVE-2023-30589 (exploit),
Improper key generation - CVE-2023-30590
Hitachi published an advisory that discusses three vulnerabilities in their Ops Center Administrator product, one of which is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. These are third-party (Apache) vulnerabilities. Hitachi has a new version for one of the affected products that mitigates the vulnerabilities.
The three reported vulnerabilities are:
Improper input validation - CVE-2023-45648,
HTTP request/response smuggling - CVE-2023-46589,
Deserialization of untrusted data - CVE-2023-46604 (KEV)(exploit)
Hitachi published an advisory that describes an incorrect default permissions vulnerability in their Hitachi Storage Plug-in for VMware vCenter. Hitachi has a new version that mitigates the vulnerability.
Hitachi published an advisory that discusses four vulnerabilities in their Command Suite products one of which is listed in CISA’s KEV catalog. These are third-party (Apache) vulnerabilities. Hitachi has new versions that mitigate the vulnerabilities.
The four reported vulnerabilities are:
Improper input validation - CVE-2015-7559,
Improper certificate validation - CVE-2018-11775,
Undescribed - CVE-2019-0222, and
Deserialization of untrusted data - CVE-2023-46604 (KEV)
Hitachi published an advisory that discusses 27 vulnerabilities in their Disk Array Systems products. These are third-party (Microsoft) vulnerabilities. Hitachi has security updates for some of the affected products.
Hitachi Energy Advisories
Hitachi Energy published an advisory that discusses an improper input validation vulnerability in their TropOS core routers. This is a third-party (ntp) vulnerability. Hitachi Energy has a new version that mitigates the vulnerability.
Hitachi Energy published an advisory that discusses three vulnerabilities in their MSM Product. These are third-party (OpenSSL) vulnerabilities. Hitachi Energy provides generic mitigation measures pending development of a fix.
The three reported vulnerabilities are:
Allocation of resources without limit or throttling - CVE-2023-2650,
Use after free - CVE-2023-0215, and
Type confusion - CVE-2023-0286
Hitachi Energy published an advisory that discusses nine vulnerabilities in their AFF660/665 series products. These are third-party vulnerabilities.
The nine reported vulnerabilities are:
Improper certificate validation - CVE-2023-0464,
Use after free (3) - CVE-2023-0215, CVE-2022-43680 (exploit), and CVE-2022-40674,
NULL pointer dereference (3) - CVE-2023-0216, CVE-2023-0401, and CVE-2023-0217
Type confusion - CVE-2023-0286, and
Double free - CVE-2022-4450,
Honeywell Advisory
Honeywell published an advisory for two vulnerabilities in a number of their smartcard readers/cards. These are third-party (HID) vulnerabilities. The first affects just the cards as sensitive information can be read from the cards. The second affects the reader as some readers can be reprogrammed by the cards to downgrade the communication channels.
Pilz Advisory
CERT-VDE published an advisory that describes two cross-site scripting vulnerabilities in the Pilz PASvisu and PMI v8xx products. Pilz has a new version for one of the affected products that mitigates the vulnerability.
QNAP Advisories
QNAP published an advisory that describes two vulnerabilities in their Photo Station product. The vulnerabilities were reported by lebr0nli. QNAP has a new version that mitigates the vulnerabilities. There is no indication that lebr0nli has been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Cross-site scripting - CVE-2023-47561, and
OS command injection - CVE-2023-47562
QNAP published an advisory that describes an unchecked return value vulnerability in their QTS and QuTS hero products. QNAP has new firmware that mitigates the vulnerability.
QNAP published an advisory that discusses an improper validation of integrity check value vulnerability in their QTS and QuTS hero products. This is a third-party (OpenSSH) vulnerability with known exploit. QNAP has new versions that mitigate the vulnerabilities.
QNAP published an advisory that describes two vulnerabilities in their QTS, QuTS hero, and QuTScloud products. The vulnerabilities were reported by duongdpt and hoangnx. QNAP has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
OS command injection - CVE-2023-47567, and
SQL injection - CVE-2023-47568
QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero, and QuTScloud products. The vulnerability was reported by nobodyisnobody. QNAP has a new firmware version that mitigates the vulnerability. There is no indication that nobodyisnobody was provided an opportunity to verify the efficacy of the fix.
QNAP published an advisory that describes three vulnerabilities in their QTS, QuTS hero, and QuTScloud products. The vulnerabilities were reported by Jiaxu Zhao and Bingwei Peng. QNAP has new firmware versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided with an opportunity to verify the efficacy of the fix.
The three reported vulnerabilities are:
Path traversal (2) - CVE-2023-45026 and CVE-2023-45027, and
Uncontrolled resource consumption - CVE-2023-45028
QNAP published an advisory that describes three OS command injection vulnerabilities in their QTS, QuTS hero and QuTScloud products. The vulnerabilities were reported by rekter0. QNAP has new firmware versions that mitigate the vulnerability. There is no indication that rekter0 the researchers have been provided with an opportunity to verify the efficacy of the fix.
QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero and QuTScloud products. The vulnerability was reported by John_p and rekter0. QNAP has new firmware versions that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
QNAP published an advisory that describes an OS command injection vulnerability in their TS, QuTS hero and QuTScloud products. The vulnerability was reported by chumen77. QNAP has a new firmware version that mitigates the vulnerability. There is no indication that chumen77 has been provided an opportunity to verify the efficacy of the fix.
QNAP published an advisory that describes a classic buffer overflow vulnerability in their QTS, QuTS hero and QuTScloud products. The vulnerability was reported by Jiaxu Zhao and Bingwei Peng. QNAP has a new firmware version that mitigates. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
QNAP published an advisory that describes eight vulnerabilities in their QTS, QuTS hero and QuTScloud products. The vulnerabilities were reported by Jiaxu Zhao and Bingwei Peng. QNAP has a new firmware version that mitigates. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The eight reported vulnerabilities are:
Classic buffer overflow (7) - CVE-2023-41273, CVE-2023-41275, CVE-2023-41276, CVE-2023-41277, CVE-2023-41278, CVE-2023-41279, and CVE-2023-41280, and
NULL pointer dereference - CVE-2023-41274,
QNAP published an advisory that describes an OS command injection vulnerability in their QTS, QuTS hero and QuTScloud. The vulnerability was reported by rekter0. QNAP has a new firmware versions that mitigate the vulnerability. There is no indication that rekter0 has been provided an opportunity to verify the efficacy of the fix.