So, for Part 2 we start with seven more vendor disclosures from Dell (2), Sick, Texas Instruments, VMware (2), and Western Digital. There are also seven vendor updates from Dell, Eaton, HPE (3), VMware (2). We also have researcher two reports of vulnerabilities in products from KiCad. Finally, we have an exploit report for products from Emerson.
Dell Advisories
Dell published an advisory describing three vulnerabilities in their Dell Wyse Device Agent. Dell has a new version that mitigates the vulnerability.
The three reported vulnerabilities are:
Improper authentication - CVE-2022-23156, and
Sensitive data exposure (2) - CVE-2022-23158 and CVE-2022-23157
Dell published an advisory describing two vulnerabilities in their Dell Wyse Management Suite. The vulnerabilities were reported by bugbounty2k20. Dell has a new version that mitigates the vulnerabilities. There is no indication that the researcher has been provided an opportunity to verify the efficacy of the fix.
The two reported vulnerabilities are:
Unrestricted file upload - CVE-2022-23155, and
Unrestricted file upload (in Log4j) - CVE-2021-44832
NOTE: This Dell published a Log4Shell advisory for their Dell Wyse Management Suite reporting that the three primary Log4j vulnerabilities were corrected in version 3.5.2. This Log4j vulnerability was not include in that advisory, nor was it corrected in that version.
Sick Advisory
Sick published an advisory discussing the Wibu Systems CodeMeter vulnerabilities in their FieldEcho product. Sick has a new version that mitigates the vulnerability.
TI Advisory
TI published an advisory describing an information disclosure vulnerability in their SimpleLink™ CC32xx/CC31xx product line. The vulnerability was reported by Francesco Benvenuto and Matt Wiseman of Cisco Talos. The report includes proof-of-concept code. TI has updates that mitigate the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
VMware Advisories
VMware published an advisory describing five vulnerabilities in their VMware ESXi, Workstation, and Fusion products. The vulnerabilities were reported by Wei and VictorV of Kunlun Lab as part of the 2021 Tianfu Cup Pwn Contest and George Noseevich and Sergey Gerasimov of SolidLab LLC. VMware has new versions that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The five reported vulnerabilities are:
Use after free - CVE-2021-22040,
Double fetch - CVE-2021-22041,
Unauthorized access - CVE-2021-22042,
Time-of-check time-of-use - CVE-2021-22043, and
Slow HTTP POST - CVE-2021-22043
VMware published an advisory describing a CLI shell injection vulnerability in their NSX Data Center for vSphere product. The vulnerability was reported by Dimitri Di Cristofaro) and Przemek Reszke from SECFORCE LTD. VMware has a new version that mitigates the vulnerability. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
Western Digital Advisory
Western Digital published an advisory describing eight vulnerabilities in their My Cloud OS 5 firmware. The vulnerabilities were reported by Sam Thomas of Pentest Ltd and Martin Rakhmanov, both via the Zero Day Initiative. Western Digital has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.
The eight reported vulnerabilities are:
Use-after-free - CVE-2020-21913 (ICU-20850) (exploit),
Improper input validation - CVE-2020-25717 (Samba),
Command injection (2) - CVE-2022-22991, CVE-2022-22992,
Insufficient verification of data authenticity - CVE-2022-22994,
Out-of-bounds write - CVE-2022-22989,
Improper authentication - CVE-2022-22990, and
Server side request forgery - CVE-2022-22993
Dell Update
Dell published an update for their Log4Shell advisory.
Eaton Update
Eaton published an update for their Log4Shell advisory.
HPE Updates
HPE published an update for their HPE ProLiant, Apollo, and Synergy Servers advisory that was originally published on February 8th, 2022. The new information includes adding HPE StoreEasy to the list of affected products.
HPE published an update for their HPE ProLiant, Apollo, Edgeline, and Synergy Servers that was originally published on February 8th, 2022. The new information includes adding HPE StoreEasy to the list of affected products.
HPE published an update for their HPE ProLiant, Apollo, and Synergy Servers that was originally published on February 8th, 2022. The new information includes adding HPE StoreEasy to the list of affected products.
VMware Updates
VMware published an update for their VMware Workstation, Fusion and ESXi that was originally published on January 4th, 2022 and most recently updated on January 27th, 2022. The new information includes adding mitigation measures for VMware Cloud Foundation 4.4 and 3.11.
VMware published an update for their Cloud Foundation advisory that was originally published on January 31st, 2022. The new information includes adding mitigation measures for VMware Cloud Foundation 3.11.
KiCad Reports
Talos published two reports (here and here) describing four vulnerabilities in the KiCad EDA. The reports contain proof-of-concept code. Talos has reported the vulnerabilities to KiCad.
The four reported vulnerabilities are:
Stack-based buffer overflow (4) CVE-2022-23804, CVE-2022-23803, CVE-2022-23947, and CVE-2022-23946
Emerson Exploit
Luis Martínez published an exploit for an unquoted search path vulnerability in the Emerson PAC Machine. There is no CVE included nor is there any indication that the vendor was contacted. This may be a 0-day exploit.