IOActive Security Advisory | PLANET Networking – Vulnerabilities Identified
Affected Product IGS-4215-16T2S Firmware Version 1.305b210528 Background IOActive had the chance to access the IGS-4215-16T2S device. IOActive identified three vulnerabilities which need attention. Timeline 2022-09-29: IOActive discovers the vulnerabilities 2023-03-29: IOActive informs Planet Technology about the identified vulnerabilities 2023-12-13: Planet released a new firmware version (1.305b231218) informing IOActive that the vulnerabilities are fixed 2024-01-09: IOActive notifies the vulnerability to INCIBE, Spanish CERT 2024-02-16: IOActive confirm that the vulnerabilities were fixed after retesting them in the new firmware version 2024-03-21: INCIBE shared the CVEs assigned with IOActive…
IOActive Security Advisory | Fortinet FortiGate – Cross-site Scripting in SSL VPN
Affected Products VersionAffectedFortiOS 7.47.4.0 through 7.4.3FortiOS 7.27.2.0 through 7.2.7FortiOS 7.07.0.0 through 7.0.13FortiOS 6.46.4 all versionsFortiProxy 7.47.4.0 through 7.4.3FortiProxy 7.27.2.0 through 7.2.9FortiProxy 7.07.0.0 through 7.0.16 Background Fortinet, Inc. (Fortinet) is a global leader of cybersecurity solutions and services that provides protection against cyber threats. It is a company that develops and sells security products and solutions, such as firewalls, endpoint security, intrusion prevention systems, web filtering, antivirus, sandbox, and VPN. FortiGate is a network security device that provides protection against cyber threats. The device can perform various…
IOActive Security Advisory | MásMóvil Comtrend Router – Multiple Vulnerabilities
Affected Products MásMóvil Comtrend Router – Version: ES_WLD71-T1_v2.0.201820HW Version: GRG-4280usFW Version: QR51S404 SW Version: MMV-C04_R10 Timeline 2023-08-24: IOActive discovers vulnerability 2023-09-12: IOActive begins vulnerability disclosure with affected parties 2024-06-10: The corresponding CNA released the CVEs to public domain. 2024-06-21: IOActive advisory published
IOActive Security Advisory | Nokia Industrial Fieldrouter (CPE) Multiple Vulnerabilities
Nokia developed 5G field routers to address the challenge of connecting older industrial equipment and vehicles reliably to private wireless networks. This aids mining companies, port operators, manufacturers, and other enterprises in adopting Industry 4.0 applications such as autonomous operations.
IOActive Security Advisory | KUNBUS Revolution Pi – Multiple Vulnerabilities
KUNBUS GmbH (KUNBUS) develops and offers products and solutions for industrial communication in automation, process, manufacturing and drive technology. This includes a comprehensive portfolio of real-time Ethernet and fieldbus-based protocol technology on state-of-the-art hardware platforms, as well as stacks suitable for the sensor level with IO-Link and IO-Link Wireless and the entry into wireless communication technology.
IOActive Security Advisory | Movistar 4G Router – Multiple Vulnerabilities
IOActive found that the Android Debug Bridge (ADB) is listening on all interfaces and gives access to a shell with root privileges; a malicious actor with access to the same network that the router is providing access to will have full control of the device. A malicious actor can send a specific payload to the gui.cgi using the ping_traceroute_process functionality to execute arbitrary commands as the privileged root user. IOActive saw a general lack of protection against cross-site request forgery (CSRF) attacks. CVE-2024-2414, CVE-2024-2415, CVE-2024-2416
IOActive Security Advisory | Hikvision Camera Denial of Service
CVE-2023-28811. The Hikvision DS-7732NI-14(B) is a 32-channel Network Video Recorder (NVR). IOActive had the opportunity to assess the DS-7732NI-I4 and identified one high-risk vulnerability. This issue could be exploited to cause a denial of service (DoS) to the device.
IOActive Security Advisory | Lamassu Douro Bitcoin ATM – Multiple Vulnerabilities
Supporting security advisory/disclosure document (CVE-2024-0175, CVE-2024-0176 and CVE-2024-0177) supporting the Lamassu Douro Bitcoin ATM research by Gabriel Gonzalez, IOActive Director of Hardware Security. IOActive had access to few of these machines, specifically to Lamassu’s Douro ATM. This provided the team with the opportunity to assess the security of these devices – more specifically, to attempt to gain full control over them – assuming the role of an attacker with the same physical access to the device that a regular customer might have.
IOActive Security Advisory | Socomec NET VISION – Multiple Vulnerabilities
IOActive Security Advisory/Disclosure document (CVE TBA) by Daniel Martinez, IOActive Senior Security Consultant, of the multiple vulnerabilities discovered in the Socomec NET VISION devices. Socomec, Inc. (Socomec) is an electrical equipment design and manufacturing company, specializing in low-voltage energy performance in terms of safety, service continuity, quality and energy efficiency. NET VISION is a professional network adapter for monitoring and controlling UPS units from a remote location. It allows direct connection of a UPS to the IPv4 or IPv6 Ethernet network, thereby enabling remote management of the UPS using a…
IOActive Advisory – ID TECH Disclosure
IOActive response to ID TECH’s advisory on the APDU stack overflow research by Josep Pi Rodriguez.