VARIoT IoT vulnerabilities database
| VAR-202308-4065 | No CVE | H3C Technology Co., Ltd. Magic R365 has a command execution vulnerability |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
H3C Technology Co., Ltd. Magic R365 is a full Gigabit wireless router.
H3C Technology Co., Ltd. Magic R365 has a command execution vulnerability, which can be exploited by attackers to gain control of the server.
| VAR-202308-2215 | CVE-2023-30705 | Samsung's Galaxy Store Fraud related to unauthorized authentication in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission. Samsung's Galaxy Store Exists in a fraudulent authentication vulnerability.Information may be obtained
| VAR-202308-3763 | No CVE | H3C Technology Co., Ltd. Magic R365 has a binary vulnerability (CNVD-2023-63799) |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Magic R365 router is a wireless router produced by H3C Technology Co., Ltd. (H3C).
H3C Technology Co., Ltd. Magic R365 has a binary vulnerability, which can be exploited by attackers to gain control of the server.
| VAR-202308-3953 | No CVE | H3C B5 has an unauthorized access vulnerability (CNVD-2023-63854) |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
H3C B5 is a router product of H3C Technology Co., Ltd.
H3C B5 has an unauthorized access vulnerability. Attackers can use this vulnerability to bypass identity verification by constructing a special request packet to obtain sensitive information of the router.
| VAR-202308-3954 | No CVE | Arris VAP2500 Remote Code Execution Vulnerability (CNVD-2023-62027) |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Arris VAP2500, a device launched by Arris Group, is a video gateway and WIFI signal booster for extending home network coverage and providing wireless connectivity.
Arris VAP2500 has a remote code execution vulnerability. The vulnerability stems from the fact that the list_mac_address.php file does not strictly filter and restrict the macaddr parameters passed in by users. Attackers can use this vulnerability to cause command injection through carefully constructed macaddr parameters.
| VAR-202308-2035 | CVE-2023-3953 | Schneider Electric of Pro-Face GP-Pro EX Buffer error vulnerability in |
CVSS V2: 4.6 CVSS V3: 5.3 Severity: MEDIUM |
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory
Buffer vulnerability exists that could cause memory corruption when an authenticated user
opens a tampered log file from GP-Pro EX. Schneider Electric of Pro-Face GP-Pro EX Exists in a buffer error vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Schneider Electric GP-Pro EX is a set of HMI interface editing and logic programming software from the French Schneider Electric company.
Schneider Electric Pro-face GP-Pro EX has a buffer overflow vulnerability
| VAR-202308-2632 | CVE-2023-40042 | TOTOLINK T10 comment parameter buffer overflow vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code. TOTOLINK T10 is a wireless network system router produced by China Zeon Electronics (TOTOLINK). The vulnerability originates from the fact that the comment parameter in setStaticDhcpConfig of /lib/cste_modules/lan.so fails to correctly verify the length of the input data. Remote attackers can exploit this vulnerability in the system execute arbitrary code or cause a denial of service attack
| VAR-202308-3044 | CVE-2023-40041 | TOTOLINK T10 pin parameter buffer overflow vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code. TOTOLINK T10 is a wireless network system router produced by China Zeon Electronics (TOTOLINK). The vulnerability is caused by the fact that the pin parameter in setWiFiWpsConfig fails to correctly verify the length of the input data. Remote attackers can use this vulnerability to execute arbitrary code on the system or cause a denial of service attack
| VAR-202308-2021 | CVE-2023-38180 | plural Microsoft Service operation interruption in the product (DoS) Vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
.NET and Visual Studio Denial of Service Vulnerability. 9) - aarch64, ppc64le, s390x, x86_64
3. ==========================================================================
Ubuntu Security Notice USN-6278-2
August 10, 2023
dotnet6, dotnet7 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in .NET.
Software Description:
- dotnet6: dotNET CLI tools and runtime
- dotnet7: dotNET CLI tools and runtime
Details:
USN-6278-1 fixed several vulnerabilities in .NET. This update
provides the corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that .NET did properly handle the execution of
certain commands. An attacker could possibly use this issue to
achieve remote code execution. (CVE-2023-35390)
Benoit Foucher discovered that .NET did not properly implement the
QUIC stream limit in HTTP/3. An attacker could possibly use this
issue to cause a denial of service. (CVE-2023-38178)
It was discovered that .NET did not properly handle the disconnection
of potentially malicious clients interfacing with a Kestrel server. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2023-38180)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
aspnetcore-runtime-6.0 6.0.121-0ubuntu1~22.04.1
aspnetcore-runtime-7.0 7.0.110-0ubuntu1~22.04.1
dotnet-host 6.0.121-0ubuntu1~22.04.1
dotnet-host-7.0 7.0.110-0ubuntu1~22.04.1
dotnet-hostfxr-6.0 6.0.121-0ubuntu1~22.04.1
dotnet-hostfxr-7.0 7.0.110-0ubuntu1~22.04.1
dotnet-runtime-6.0 6.0.121-0ubuntu1~22.04.1
dotnet-runtime-7.0 7.0.110-0ubuntu1~22.04.1
dotnet-sdk-6.0 6.0.121-0ubuntu1~22.04.1
dotnet-sdk-7.0 7.0.110-0ubuntu1~22.04.1
dotnet6 6.0.121-0ubuntu1~22.04.1
dotnet7 7.0.110-0ubuntu1~22.04.1
In general, a standard system update will make all the necessary changes. 9) - aarch64, s390x, x86_64
3. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: rh-dotnet60-dotnet security, bug fix, and enhancement update
Advisory ID: RHSA-2023:4641-01
Product: .NET Core on Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4641
Issue date: 2023-08-14
CVE Names: CVE-2023-35390 CVE-2023-38180
=====================================================================
1. Summary:
An update for rh-dotnet60-dotnet is now available for .NET Core on Red Hat
Enterprise Linux.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
.NET Core on Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64
.NET Core on Red Hat Enterprise Linux Server (v. 7) - x86_64
.NET Core on Red Hat Enterprise Linux Workstation (v. 7) - x86_64
3. Description:
.NET is a managed-software framework. It implements a subset of the .NET
framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now
available. The updated versions are .NET SDK 6.0.121 and .NET Runtime
6.0.21.
Security Fix(es):
* dotnet: RCE under dotnet commands (CVE-2023-35390)
* dotnet: Kestrel vulnerability to slow read attacks leading to Denial of
Service attack (CVE-2023-38180)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
2228621 - CVE-2023-38180 dotnet: Kestrel vulnerability to slow read attacks leading to Denial of Service attack
2228622 - CVE-2023-35390 dotnet: RCE under dotnet commands
6. Package List:
.NET Core on Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
rh-dotnet60-dotnet-6.0.121-1.el7_9.src.rpm
x86_64:
rh-dotnet60-aspnetcore-runtime-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-aspnetcore-targeting-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-apphost-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-debuginfo-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-host-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-hostfxr-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-runtime-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-sdk-6.0-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-sdk-6.0-source-built-artifacts-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-targeting-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-templates-6.0-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-netstandard-targeting-pack-2.1-6.0.121-1.el7_9.x86_64.rpm
.NET Core on Red Hat Enterprise Linux Server (v. 7):
Source:
rh-dotnet60-dotnet-6.0.121-1.el7_9.src.rpm
x86_64:
rh-dotnet60-aspnetcore-runtime-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-aspnetcore-targeting-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-apphost-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-debuginfo-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-host-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-hostfxr-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-runtime-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-sdk-6.0-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-sdk-6.0-source-built-artifacts-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-targeting-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-templates-6.0-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-netstandard-targeting-pack-2.1-6.0.121-1.el7_9.x86_64.rpm
.NET Core on Red Hat Enterprise Linux Workstation (v. 7):
Source:
rh-dotnet60-dotnet-6.0.121-1.el7_9.src.rpm
x86_64:
rh-dotnet60-aspnetcore-runtime-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-aspnetcore-targeting-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-apphost-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-debuginfo-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-host-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-hostfxr-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-runtime-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-sdk-6.0-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-sdk-6.0-source-built-artifacts-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-targeting-pack-6.0-6.0.21-1.el7_9.x86_64.rpm
rh-dotnet60-dotnet-templates-6.0-6.0.121-1.el7_9.x86_64.rpm
rh-dotnet60-netstandard-targeting-pack-2.1-6.0.121-1.el7_9.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2023-35390
https://access.redhat.com/security/cve/CVE-2023-38180
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCAAGBQJk2ox4AAoJENzjgjWX9erEzm4P/j9KGuwQcPYINF/hHv894DBB
jd4ssZNnb1cmEPcILEnWbjpj3Tye/4C1TFMP4Gwk8iYCks7XB3OhkUxoOnmH5AL+
yNSTTkFTDwHtPDVHnfxrEb5mBi5xPGowh3BTcxI5T1IcQD6Iq22PK4kul35oB1JA
ONxq0IJAjGosZE097ZLzI5wDYriW7j4ztYpj7bb17PeB8hi+DM3+xFGsQF/bEzco
cabRwo9sqeUc3g9UMs4BptqwIIFYBawimos9EHxnW+VWPrA/xxvdnMV3k9E9t/35
OiLuG8U6oxxE+s3AZkAABNPVLK0w8xdTCgSce0hrK90o/BuSPEMqEpDV/uyQ3YWT
MflES8m3hUk2Dn54u0oIeugEy/19mNxGm59LSVEC6v/KpUz8dIaNmHQN+/m9vFKH
CGCcqxBYhsv7V4Khm6KFL1TjJqx2PqVGBlIjzAOEl6N1f3ZYROYIWlbrh4F3u2yB
9hPXsGNqBak+Tjqtsxz/NmADsHU2vD99u3O5OUTzxEvt4QBUq9ccfRB8C4j47mcR
Sd9y3aT9D/aYRfTFTUfdaLFr5acKBQzskH4eDmBWin0nJFNRCa71dq1kHbywTRqA
1UF98WUX3ERSEkqPb2uSpg0u7/OUD5VjYxFwH5yHk0KuSi/54G88bEUDR0OyK/zY
/2tvafvaLc1Di9EP6HOd
=uint
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
| VAR-202308-2521 | CVE-2023-35391 | plural Microsoft A vulnerability in which information is disclosed in a product |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
| VAR-202308-2103 | CVE-2023-4203 | Advantech EKI-1524-CE / EKI-1522 / EKI-1521 Cross Site Scripting |
CVSS V2: - CVSS V3: 9.0 Severity: CRITICAL |
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface. St. P\xf6lten UAS
-------------------------------------------------------------------------------
title| Multiple XSS in Advantech
product| Advantech EKI-1524-CE series, EKI-1522 series,
| EKI-1521 series
vulnerable version| <=1.21 (CVE-2023-4202), <=1.24 (CVE-2023-4203)
fixed version| 1.26
CVE number| CVE-2023-4202, CVE-2023-4203
impact| Medium
homepage| https://advantech.com
found| 2023-05-04
by| R. Haas, A. Resanovic, T. Etzenberger, M. Bineder
| This vulnerability was discovery during research at
| St. P\xf6lten UAS, supported and coordinated by CyberDanube.
|
| https://fhstp.ac.at | https://cyberdanube.com
-------------------------------------------------------------------------------
Vendor description
-------------------------------------------------------------------------------
\x93Advantech\x92s corporate vision is to enable an intelligent planet. The company
is a global leader in the fields of IoT intelligent systems and embedded
platforms. To embrace the trends of IoT, big data, and artificial intelligence,
Advantech promotes IoT hardware and software solutions with the Edge
Intelligence WISE-PaaS core to assist business partners and clients in
connecting their industrial chains. Advantech is also working with business
partners to co-create business ecosystems that accelerate the goal of
industrial intelligence.\x94
Source: https://www.advantech.com/en/about
Vulnerable versions
-------------------------------------------------------------------------------
EKI-1524-CE series / 1.21 (CVE-2023-4202)
EKI-1522-CE series / 1.21 (CVE-2023-4202)
EKI-1521-CE series / 1.21 (CVE-2023-4202)
EKI-1524-CE series / 1.24 (CVE-2023-4203)
EKI-1522-CE series / 1.24 (CVE-2023-4203)
EKI-1521-CE series / 1.24 (CVE-2023-4203)
Vulnerability overview
-------------------------------------------------------------------------------
1) Stored Cross-Site Scripting (XSS) (CVE-2023-4202, CVE-2023-4203)
Two stored cross-site scripting vulnerabilities has been identified in the
firmware of the device. The first XSS was identified in the "Device Name" field
and the second XSS was found in the "Ping" tool. This can be exploited in the
context of a victim's session.
1.1) Stored XSS in Device Name CVE-2023-4202
The first vulnerability can be triggerd by setting the device name
("System->Device Name") to the following value:
"><script>alert("document.cookie")</script>
This code prints out the cached cookies to the screen.
1.2) Stored XSS in Ping Function CVE-2023-4203
The second XSS vulnerability can be found in "Tools->Ping". The following GET
request prints the current cached cookies of a user's session to the screen.
http://$IP/cgi-bin/ping.sh?random_num=2013&ip=172.16.0.141%3b%20<script>alert(1)</script>&size=56&count=1&interface=eth0&_=1682793104513
An alternative to the used payload is using "onmouseover" event tags. In this
case it prints out the number "1337":
" onmousemove="alert(1337)"
The vulnerability was manually verified on an emulated device by using the
MEDUSA scalable firmware runtime (https://medusa.cyberdanube.com).
Solution
-------------------------------------------------------------------------------
Upgrade to the newest available firmware.
Workaround
-------------------------------------------------------------------------------
None.
Recommendation
-------------------------------------------------------------------------------
Advantech customers are advised to upgrade the firware to the latest
available version.
Contact Timeline
-------------------------------------------------------------------------------
2023-05-16: Contacting vendor via security contact.
2023-05-24: Contact stated that issue 1.1) is solved after firmware v1.21.
The contact is trying to reproduce issue 1.2; Gave advice to
reproduce issue.
2023-05-25: Contact stated that new firmware should resolve the issue.
2023-06-03: Sent new payload to the vendor.
2023-06-05: Vendor asked for clarification; Sent further explaination to the
contact; Vendor contact said he knows a solution.
2023-06-22: Asked for an update; Contact stated that the beta firmware should
resolve the issues.
2023-06-27: Asked for the release date.
2023-07-04: Contact stated, that they are currently doing QA tests.
2023-07-06: Asked if issue 1.1 is really resolved to be released; Vendor stated
that it can be published.
2023-07-17: Assigned CVE numbers for the issues. Asked for an update.
2023-07-18: Vendor contact stated that the firmware will be released end of
July.
2023-08-07: Asked contact for the new firmware version.
2023-08-08: Received version 1.26 as the official released firmware with fixes.
Coordinated release of security advisory.
Web: https://www.fhstp.ac.at/
Twitter: https://twitter.com/fh_stpoelten
Mail: mis at fhstp dot ac dot at
EOF T. Weber / @2023
| VAR-202308-2104 | CVE-2023-4202 | Advantech EKI-1524-CE / EKI-1522 / EKI-1521 Cross Site Scripting |
CVSS V2: - CVSS V3: 9.0 Severity: CRITICAL |
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface. St. P\xf6lten UAS
-------------------------------------------------------------------------------
title| Multiple XSS in Advantech
product| Advantech EKI-1524-CE series, EKI-1522 series,
| EKI-1521 series
vulnerable version| <=1.21 (CVE-2023-4202), <=1.24 (CVE-2023-4203)
fixed version| 1.26
CVE number| CVE-2023-4202, CVE-2023-4203
impact| Medium
homepage| https://advantech.com
found| 2023-05-04
by| R. Haas, A. Resanovic, T. Etzenberger, M. Bineder
| This vulnerability was discovery during research at
| St. P\xf6lten UAS, supported and coordinated by CyberDanube.
|
| https://fhstp.ac.at | https://cyberdanube.com
-------------------------------------------------------------------------------
Vendor description
-------------------------------------------------------------------------------
\x93Advantech\x92s corporate vision is to enable an intelligent planet. The company
is a global leader in the fields of IoT intelligent systems and embedded
platforms. To embrace the trends of IoT, big data, and artificial intelligence,
Advantech promotes IoT hardware and software solutions with the Edge
Intelligence WISE-PaaS core to assist business partners and clients in
connecting their industrial chains. Advantech is also working with business
partners to co-create business ecosystems that accelerate the goal of
industrial intelligence.\x94
Source: https://www.advantech.com/en/about
Vulnerable versions
-------------------------------------------------------------------------------
EKI-1524-CE series / 1.21 (CVE-2023-4202)
EKI-1522-CE series / 1.21 (CVE-2023-4202)
EKI-1521-CE series / 1.21 (CVE-2023-4202)
EKI-1524-CE series / 1.24 (CVE-2023-4203)
EKI-1522-CE series / 1.24 (CVE-2023-4203)
EKI-1521-CE series / 1.24 (CVE-2023-4203)
Vulnerability overview
-------------------------------------------------------------------------------
1) Stored Cross-Site Scripting (XSS) (CVE-2023-4202, CVE-2023-4203)
Two stored cross-site scripting vulnerabilities has been identified in the
firmware of the device. The first XSS was identified in the "Device Name" field
and the second XSS was found in the "Ping" tool. This can be exploited in the
context of a victim's session.
1.1) Stored XSS in Device Name CVE-2023-4202
The first vulnerability can be triggerd by setting the device name
("System->Device Name") to the following value:
"><script>alert("document.cookie")</script>
This code prints out the cached cookies to the screen.
1.2) Stored XSS in Ping Function CVE-2023-4203
The second XSS vulnerability can be found in "Tools->Ping". The following GET
request prints the current cached cookies of a user's session to the screen.
http://$IP/cgi-bin/ping.sh?random_num=2013&ip=172.16.0.141%3b%20<script>alert(1)</script>&size=56&count=1&interface=eth0&_=1682793104513
An alternative to the used payload is using "onmouseover" event tags. In this
case it prints out the number "1337":
" onmousemove="alert(1337)"
The vulnerability was manually verified on an emulated device by using the
MEDUSA scalable firmware runtime (https://medusa.cyberdanube.com).
Solution
-------------------------------------------------------------------------------
Upgrade to the newest available firmware.
Workaround
-------------------------------------------------------------------------------
None.
Recommendation
-------------------------------------------------------------------------------
Advantech customers are advised to upgrade the firware to the latest
available version.
Contact Timeline
-------------------------------------------------------------------------------
2023-05-16: Contacting vendor via security contact.
2023-05-24: Contact stated that issue 1.1) is solved after firmware v1.21.
The contact is trying to reproduce issue 1.2; Gave advice to
reproduce issue.
2023-05-25: Contact stated that new firmware should resolve the issue.
2023-06-03: Sent new payload to the vendor.
2023-06-05: Vendor asked for clarification; Sent further explaination to the
contact; Vendor contact said he knows a solution.
2023-06-22: Asked for an update; Contact stated that the beta firmware should
resolve the issues.
2023-06-27: Asked for the release date.
2023-07-04: Contact stated, that they are currently doing QA tests.
2023-07-06: Asked if issue 1.1 is really resolved to be released; Vendor stated
that it can be published.
2023-07-17: Assigned CVE numbers for the issues. Asked for an update.
2023-07-18: Vendor contact stated that the firmware will be released end of
July.
2023-08-07: Asked contact for the new firmware version.
2023-08-08: Received version 1.26 as the official released firmware with fixes.
Coordinated release of security advisory.
Web: https://www.fhstp.ac.at/
Twitter: https://twitter.com/fh_stpoelten
Mail: mis at fhstp dot ac dot at
EOF T. Weber / @2023
| VAR-202308-0232 | CVE-2023-38683 | Siemens' JT2Go and Teamcenter Visualization Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in JT2Go (All versions < V14.2.0.5), Teamcenter Visualization V13.2 (All versions < V13.2.0.14), Teamcenter Visualization V14.1 (All versions < V14.1.0.10), Teamcenter Visualization V14.2 (All versions < V14.2.0.5). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted TIFF file. This could allow an attacker to execute code in the context of the current process. Siemens' JT2Go and Teamcenter Visualization Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202308-0234 | CVE-2023-38532 | Siemens' parasolid and Teamcenter Visualization Vulnerability in resource allocation without restrictions or throttling in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.171), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.3). The affected application contains a stack exhaustion vulnerability while parsing a specially crafted X_T file. This could allow an attacker to cause denial of service condition. Siemens' parasolid and Teamcenter Visualization Exists in a vulnerability in resource allocation without restrictions or throttling.Service operation interruption (DoS) It may be in a state
| VAR-202308-0238 | CVE-2023-38531 | Siemens' parasolid and Teamcenter Visualization Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.184), Teamcenter Visualization V14.1 (All versions), Teamcenter Visualization V14.2 (All versions), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. Siemens' parasolid and Teamcenter Visualization Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202308-0242 | CVE-2023-38530 | Siemens' parasolid and Teamcenter Visualization Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.171), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.3). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. Siemens' parasolid and Teamcenter Visualization Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202308-0241 | CVE-2023-38529 | Siemens' parasolid and Teamcenter Visualization Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.184), Teamcenter Visualization V14.1 (All versions), Teamcenter Visualization V14.2 (All versions), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. Siemens' parasolid and Teamcenter Visualization Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202308-0235 | CVE-2023-38528 | Siemens' parasolid and Teamcenter Visualization Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.197), Parasolid V35.1 (All versions < V35.1.184), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted X_T file. This could allow an attacker to execute code in the context of the current process. Siemens' parasolid and Teamcenter Visualization Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202308-0239 | CVE-2023-38527 | Siemens' parasolid and Teamcenter Visualization Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Teamcenter Visualization V14.1 (All versions), Teamcenter Visualization V14.2 (All versions), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. Siemens' parasolid and Teamcenter Visualization Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202308-0237 | CVE-2023-38526 | Siemens' parasolid and Teamcenter Visualization Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.171), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.3). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. Siemens' parasolid and Teamcenter Visualization Exists in an out-of-bounds read vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state