For Part 2 we have six additional vendor disclosures from Dell, Supermicro (3), VMware, and Westermo. There are 24 bulk vendor updates for products from ELECOM (6), Schneider (7), and Siemens (11). Finally, we have two exploits for products from OpenPLC and strongSwan.
Advisories
Dell Advisory - Dell published an advisory that discusses three vulnerabilities (all listed in CISA’s KEV catalog) in their ThinOS products.
Supermicro Advisory #1 - Supermicro published an advisory that discusses a microarchitectural predictor vulnerability in multiple Supermicro products.
Supermicro Advisory #2 - Supermicro published an advisory that discusses three vulnerabilities in multiple Supermicro products.
Supermicro Advisory #3 - Supermicro published an advisory that discusses an improper initialization vulnerability in multiple Supermicro products.
VMware Advisory - Broadcom published an advisory that describes a TOCTOU race condition vulnerability in the VMware Fusion product.
Westermo Advisory - Westermo published an advisory that discusses an out-of-bounds read vulnerability in their Merlin and Virtual Access GW Series OSPF products.
Updates
Bulk Vendor Updates – ELECOM (6)
Bulk Vendor Updates – Schneider (7)
Bulk Vendor Updates – Siemens (11)
Exploits
OpenPLC Exploit - Unicorn-hyh published an exploit for a path traversal vulnerability in OpenPLC-v3.
StrongSwan Exploit - Indoushka published a Metasploit module for an integer underflow vulnerability in the strongSwan EAP-TTLS implementation.
For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-6f8 - subscription required.