Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cases closed and filled in IPs notified #699

Merged
merged 2 commits into from
Jan 2, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 11 additions & 1 deletion _cases/2023/DIVD-2023-00011.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ layout: case
title: "FortiNAC and FortiWeb RCE Vulnerability"
author: Max van der Horst
lead: Victor Pasman
status: Open
status: Closed
excerpt: "Fortinet has released security updates for its FortiNAC and FortiWeb products to fix two critical vulnerabilities."
researchers:
- Stan Plasmeijer
Expand Down Expand Up @@ -37,6 +37,16 @@ timeline:
- start: 2023-02-21
end:
event: "First version of this casefile."
- start: 2023-02-23
end:
event: "DIVD starts researching fingerprint."
- start: 2023-03-23
end:
event: "Fingerprint found."
- start: 2023-12-20
end:
event: "Case closed."
ips: 0
---

## Summary
Expand Down
7 changes: 6 additions & 1 deletion _cases/2023/DIVD-2023-00021.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ layout: case
title: "Multiple vulnerabilities in Danfoss AK-EM 100"
author: Max van der Horst
lead: Max van der Horst
status: Open
status: Closed
excerpt: "Danfoss AK-EM 100 has multiple web-related vulnerabilities. It is advised to phase out this product, as this product is End of Life."
researchers:
- Jony Schats (HackDefense)
Expand Down Expand Up @@ -44,9 +44,14 @@ timeline:
- start: 2023-05-26
end:
event: "DIVD performs first mailrun."
- start: 2023-12-20
end:
event: "Case closed."
jekyll-secinfo:
cve:
url: /cves/CVE-

ips: 52
---

## Summary
Expand Down
12 changes: 10 additions & 2 deletions _cases/2023/DIVD-2023-00022.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ layout: case
title: "OS command injection vulnerability of Zyxel firewalls"
author: Stan Plasmeijer
lead: Ralph Horn
status: Open
status: Closed
excerpt: "Zyxel has released patches for an OS command injection vulnerability found by TRAPA Security and urges uses to install them for optimal protection."
researchers:
- Axel Boesenach
Expand Down Expand Up @@ -36,7 +36,15 @@ timeline:
event: "DIVD starts researching a way to identify Zyxel devices."
- start: 2023-05-10
end:
event: "DIVD starts scanning the internet for vulnerable instances. "
event: "DIVD starts scanning the internet for vulnerable instances."
- start: 2023-05-30
end:
event: "DIVD starts notifying customers with a vulnerable instance."
- start: 2023-12-20
end:
event: "Case closed."

ips: 46701
---

## Summary
Expand Down
7 changes: 6 additions & 1 deletion _cases/2023/DIVD-2023-00025.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ layout: case
title: "Multiple vulnerabilities in Danfoss AK-SM800A"
author: Max van der Horst
lead: Max van der Horst
status: Open
status: Closed
excerpt: "Danfoss AK-SM800A has multiple web-related vulnerabilities. It is advised to install the provided patch."
researchers:
- Jony Schats (HackDefense)
Expand Down Expand Up @@ -42,9 +42,14 @@ timeline:
- start: 2023-09-27
end:
event: "DIVD starts notifying customers with a vulnerable instance."
- start: 2023-12-20
end:
event: "Case closed."
jekyll-secinfo:
cve:
url: /cves/CVE-

ips: 1062
---

## Summary
Expand Down