This week we have three vendor disclosures from HPE and Moxa (2). There are two vendor updates from Moxa and Palo Alto Networks. We have six researcher reports of vulnerabilities in products from ABB (5) and Four-Faith. Finally, we have an exploit for a vulnerability in products from Palo Alto Networks.
HPE Advisory
HPE published an advisory that discusses seven vulnerabilities (three with publicly available exploits) in their OSS Console (UOC) and Unified OSS Console Assurance Monitoring (UOCAM) products. These are third-party vulnerabilities. HPE has new versions that mitigate the vulnerabilities.
The seven reported vulnerabilities are:
Inefficient regular expression complexity - CVE-2024-21538 (exploit),
Exposure of sensitive information to an unauthorized actor - CVE-2024-23944,
Cross-site scripting - CVE-2024-37629 (exploit),
Allocation of resources without limit or throttling - CVE-2024-38808,
Uncontrolled resource consumption - CVE-2024-38809,
Injection - CVE-2024-47764,
Improper validation of syntactic correctness of input - CVE-2024-6763 (contains proof-of-concept code)
Moxa Advisories
Moxa published an advisory that describes two vulnerabilities in multiple Moxa products. The vulnerabilities were reported by Lars Haulin. Moxa has new versions that mitigate the vulnerabilities.
The two reported vulnerabilities are:
Reliance on security through obscurity - CVE-2024-9138,
OS command injection - CVE-2024-9140
Moxa published an advisory that describes a cryptographic algorithm security enhancement in their TN-G4500 Series products. The enhancement is included in a new version of the product.
Palo Alto Networks Update
Palo Alto Networks published an update for their Firewall Denial of Service advisory that was originally published on December 26th, 2024. The new information includes:
Clarifying affected products and platforms, and
Updating Workarounds and Mitigations.
Moxa Update
Moxa published an update for their VPort 07-3 Series advisory that was originally published on December 4th, 2024. The new information includes correcting CVE-2024-9404 information.
ABB Reports
Zero Science published five reports about vulnerabilities (all with publicly available exploits) in the ABB Cylon Aspect. Three of the vulnerabilities were previously reported by ABB. Zero Science reports that the vendor will not fix two of the vulnerabilities because “factory test scripts are always present in upgrade bundle but always deleted unless the device is under manufacture.” One vulnerability will be fixed in v4.0.
The five reported vulnerabilities are:
Command injection - ZSL-2025-5894 (no fix) (exploit),
Cross-site scripting - ZSL-2025-5893 (no fix) (exploit),
Content injection - ZSL-2025-5892 (to be fixed in v4.0) (exploit),
Shell command execution - ZSL-2024-5891 (exploit), and
Path traversal - ZSL-2024-5890 (exploit)
Four-Faith Report
VulnCheck published a report that describes an OS command injection vulnerability in the Four-Faith industrial routers. The report includes POC code. VulnCheck reports that this vulnerability has been exploited in the wild. VulnCheck provides a Suricata rule to detect the vulnerability. Four-Faith has been notified of the vulnerability.
NOTE: Since the affected products are of Chinese manufacture and unlikely to be employed by federal agencies, it will be interesting to see if CISA adds this vulnerability to their Known Exploited Vulnerabilities catalog.
Palo Alto Networks Exploit
WatchTowr published a Metasploit module for two vulnerabilities in the Palo Alto Networks PAN-OS management web interface. The vulnerabilities were previously reported by Palo Alto Networks and both are listed in CISA’s KEV catalog.
The two vulnerabilities included are:
Missing authentication for critical function - CVE-2024-0012, and
OS command injection - CVE-2024-9474