With this being the Saturday after Patch Tuesday, we have a lot to cover. In Part 1, we have 15 vendor disclosures from Carestream, Dell, Draeger (2), Eaton, GE Healthcare, HPE (4), Moxa (2), Palo Alto Networks, and QNAP (2).
Carestream Advisory
Carestream published an advisory discusses two vulnerabilities in their Image Suite systems. These are third-party (Microsoft) vulnerabilities. Carestream reports that the applicable Microsoft patches have been qualified on the affected products.
The two reported vulnerabilities are:
Use after free - CVE-2021-31166, and
Remote code execution - CVE-2022-21907 (exploit)
Dell Advisory
Dell published an advisory discussing two vulnerabilities in their Dell Wyse Windows Embedded System. These are third-party (Google) vulnerabilities. Dell has new versions that mitigate the vulnerabilities.
The two reported vulnerabilities are:
Undescribed - CVE-2021-4098,
Use after free - CVE-2021-4102
Draeger Advisories
Draeger published an advisory describing a use of an outdated operating system vulnerability in their Infinity Acute Care System workstations. Draeger provides generic workarounds including closing or covering data interfaces.
Draeger published an advisory describing an unsupported third-party (TLS 1.0) application vulnerability in their Gateway VF7.2 and VF9.0 products. Draeger reports that while TLS 1.0 has been deprecated by the Internet Engineering Task Force, it’s use is still required for these products.
Eaton Advisory
Eaton published an advisory discussing the INFRA:HALT vulnerabilities in their easyControl EC4P PLCs. Eaton notes that these PLCs are reaching End-of-Life and will not be updated.
GE Advisory
GE Healthcare published an advisory discussing the PwnKit vulnerabilities in their product line. GE Healthcare is currently assessing their products to determine the impact of these vulnerabilities.
HPE Advisories
HPE published an advisory discussing an insufficient control flow management vulnerability in their HPE ProLiant, Apollo, and Synergy Servers. This is a third-party (Intel) vulnerability. HPE has a firmware update that mitigates the vulnerability.
HPE published an advisory describing 16 vulnerabilities in their HPE ProLiant, Apollo, Edgeline, and Synergy Servers. These are third-party (Intel) vulnerabilities. HPE has updated firmware that mitigates these vulnerabilities.
The sixteen reported vulnerabilities are:
Improper access control (3) - CVE-2021-0091, CVE-2021-0092, and CVE-2021-0124,
Incorrect default permissions - CVE-2021-0093,
Insufficient flow control management - CVE-2021-0099 and CVE-2021-0103,
Unchecked return value - CVE-2021-0107,
NULL pointer dereference - CVE-2021-0111,
Unlisted - CVE-2021-0114, CVE-2021-0117,
Buffer overflow - CVE-2021-0115,
Out-of-bounds write - CVE-2021-0116,
Out-of-bounds read - CVE-2021-0118,
Improper initialization - CVE-2021-0119 and CVE-2021-0125, and
Improper input validation - CVE-2021-0156
HPE published an advisory discussing three vulnerabilities in their HPE ProLiant, Apollo, and Synergy Servers. These are third-party (Intel) vulnerabilities. HPE has updated firmware that mitigates the vulnerabiliteis.
The three reported vulnerabilities are:
Privilege escalation - CVE-2021-0060,
Improper locking - CVE-2021-0147, and
Denial of service - CVE-2021-33068
HPE published an advisory discussing five vulnerabilities in their Samba on NonStop products. These are third-party (Samba) vulnerabilities. HPE provides workarounds from Samba pending development of fixes.
The five reported vulnerabilities are:
Plain-text authentication - CVE-2016-2124,
Privilege escalation - CVE-2020-25717,
Fragment injection - CVE-2021-23192,
Race condition - CVE-2021-43566 (exploit), and
Out-of-bounds read/write - CVE-2021-44142
Moxa Advisories
Moxa published an advisory describing two vulnerabilities in their MXview Series Network Management Software. These vulnerabilities were reported by Patrick DeSantis of Talos. Moxa has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Use of hard-coded credentials - CVE-2021-40390, and
Clear-text transmission of sensitive information - CVE-2021-40392 (report contains proof-of-concept code)
Moxa published an advisory describing a hard-coded credentials vulnerability in their EDR-G903 Series, EDR-G902 Series, and EDR-G810 Series Secure Routers. Moxa has new version that mitigate the vulnerability.
Palo Alto Advisory
Palo Alto Networks published an advisory describing a URL filtering vulnerability in their PAN-OS software. The vulnerability was reported by Chris Johnston of PricewaterhouseCoopers. Palo Alto Networks has new versions that mitigate the vulnerability. There is no indication that Johnston has been provided an opportunity to verify the efficacy of the fix.
QNAP Advisories
QNAP published an advisory discussing three vulnerabilities in Samba. QNAP is investigating the potential impact of these third-party vulnerabilities.
The three reported vulnerabilities are:
Information leak - CVE-2021-44141,
Out-of-bounds read/write - CVE-2021-44142, and
Privilege escalation - CVE-2022-0336
QNAP published an advisory describing an improper authentication vulnerability in their Kazoo Server. The vulnerability was reported by XUELIANG SUN. QNAP has a new version that mitigates the vulnerability. There is no indication that XUELIANG has been provided an opportunity to verify the efficacy of the fix.