It is beginning to look like multipart reports are going to be the standard for this weekly update. This week in Part 1 we have 14 vendor disclosures from Aveva, Axis, Broadcom (2), WECON, HPE (6), Kunbus, Mitsubishi, and Moxa.
Aveva Advisory
Aveva published an advisory describing a use of clear text credential storage in their System Platform 2020. The vulnerability was reported by Sharon Brizinov of Claroty as well as Ilya Karpov, Evgeniy Druzhinin and Konstantin Kondratev of Rostelecom-Solar. Aveva has an update that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix. Aveva reports that the vulnerability was coordinated with NCCIC-ICS.
Axis Advisory
Axis published an advisory describing a DLL hijacking vulnerability in their IP Utility. The vulnerability was reported by SeungYun Lee from the Korea University. Axis has a new version that mitigates the vulnerability. There is no indication that Seung has been provided an opportunity to verify the efficacy of the fix.
Broadcom Advisories
Broadcom published an advisory describing a use of hard-coded credentials vulnerability in their Fabric OS. The vulnerability was reported by Cody Martin from Black Lantern Security. The report includes proof of concept code. Broadcom has a new version that mitigates the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.
Broadcom published an advisory describing an authenticated privilege file read vulnerability in their Fabric OS. The vulnerability was reported by Cody Martin from Black Lantern Security. The report includes proof of concept code. Broadcom has a new version that mitigates the vulnerability. There is no indication that Martin has been provided an opportunity to verify the efficacy of the fix.
WECON Advisory
INCIBE-CERT published an advisory two vulnerabilities in the WECON LeviStudioU. The vulnerabilities were reported by Natnael Samson via the Zero Day Initiative. Those reports had been coordinated with NCCIC-ICS. No mitigation measures have been reported.
The two reported vulnerabilities are:
Stack-based buffer overflow (2) - ZDI-22-345 and ZDI-22-344
HPE Advisories
HPE published an advisory describing a host header injection vulnerability in their Integrated Lights-Out 4. The vulnerability was reported by Ken Pyle of Cybir. HPE has a new version that mitigates the vulnerability. There is no indication that Pyle has been provided an opportunity to verify the efficacy of the fix.
HPE published an advisory describing a buffer overflow vulnerability in their iLO Amplifier Pack. HPE has a new version that mitigates the vulnerability.
HPE published an advisory describing an information disclosure vulnerability in their Fibre Channel and SAN Switches. This is a third-party vulnerability (Broadcom – see above). HPE has a new firmware version that mitigates the vulnerability.
HPE published an advisory describing an authentication bypass vulnerability in their Fibre Channel and SAN Switches. This is a third-party vulnerability (Broadcom – see above). HPE has a new firmware version that mitigates the vulnerability.
HPE published an advisory discussing the Log4Shell vulnerabilities in their Universal IoT. HPE has an update that mitigates the vulnerabilities.
HPE published an advisory describing a buffer overflow vulnerability in their Gen10 and Gen10 Plus Synergy Servers. HPE has an update that mitigates the vulnerability.
Kunbus Advisory
Kunbus published an advisory describing two vulnerabilities in their Revolution PI base modules. The vulnerabilities were reported by Paolo Coba and Nicola Mezzetti. Kunbus has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Username enumeration, and
Authentication bypass.
Mitsubishi Advisory
Mitsubishi published an advisory describing nine vulnerabilities in their Energy Saving Data Collecting Server (EcoWebServerIII). These are third-party vulnerabilities. Mitsubsihi has new versions that mitigate the vulnerabilities.
The nine reported vulnerabilities are:
Cross-site scripting (7) - CVE-2016-10735 (exploit), CVE-2018-14040 (exploit), CVE-2018-14042 (exploit), CVE-2018-20676, CVE-2019-8331 (exploit), CVE-2020-11022 (exploit), and CVE-2020-11023 (exploit)
Uncontrolled resource consumption - CVE-2017-18214, and
Improperly controlled modification of dynamically-determined object attributes - CVE-2020-7746 (exploit)
Moxa Advisory
Moxa published an advisory describing a channel accessible by non-endpoint vulnerability in their MGate MB3170/MB3270/MB3280/MB3480 Series Protocol Gateways. The vulnerability was reported by Pawan Sable and Dr. Faruk Kazi from CoE-CNDS Lab. Moxa has a patch that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.