For Part 2 we have five additional vendor disclosures from Arista,
HPE, Supermicro, WAGO, and Yokogawa. There are ten vendor updates from Broadcom
(3), CODESYS (2), HP, HPE, and Schneider (3). We also have three researcher
reports for products from Sante, Linksys, and Solax. Finally, we have three exploits
for products from FortiGuard, Palo Alto Networks, and SolarWinds.
Advisories
Arista Advisory -
Arista published an
advisory that describes six vulnerabilities in their Next Generation
Firewall.
HPE Advisory - HPE
published an
advisory that discusses an improper handling of values vulnerability in
their ProLiant DL/ML/XD, Synergy, Edgeline, MicroServer.
Supermicro Advisory -
Supermicro published an
advisory that discusses 11 vulnerabilities in multiple Supermicro products.
WAGO Advisory - CERT-VDE
published an advisory
that describes four vulnerabilities in the WAGO Industrial-Managed-Switch 0852-XXXX
products.
Yokogawa Advisory -
Yokogawa published an
advisory that describes six vulnerabilities in their Vnet/IP Interface
Package.
Updates
Broadcom Update #1 -
Broadcom published an
update for their Brocade Fabric OS advisory that was originally published
on August 1st, 2023.
Broadcom Update #2 - Broadcom published an
update for their Brocade Fabric OS advisory that was originally published
on May 17th, 2017.
Broadcom Update #3 - Broadcom published an
update for their rsynd advisory that was originally published on September
13, 2022.
CODESYS Update #1 - CODESYS published an
update for their CODESYS Control advisory that was originally published on
December 1st, 2025.
CODESYS Update #2 - CODESYS published an
update for their CODESYS Control advisory that was originally published on December
1st, 2025.
HP Update - HP published
an update for their LaserJet advisory that was originally published on November
13th, 2025, and most recently updated on December 10th,
2025.
HPE Update - HPE
published an
update for their Aruba Networking EdgeConnect advisory that was originally
published on January 14th, 2026.
Schneider Update #1 - Schneider published an
update for their EcoStruxure Power Operation advisory that was originally
published on July 8th, 2025.
Schneider Update #2 - Schneider published an
update for their EcoStruxure Foxboro DCS advisory that was originally
published on December 9th, 2025.
Schneider Update #3 - Schneider published an
update for their Uni-Telway Driver advisory that was originally published
on February 11th, 2025, and most recently updated on January 13th,
2026.
Researcher Reports
Linksys Report - SySS
Tech published a report
that describes six vulnerabilities (with proof-of-concept code) in the Linksys MR9600
and MX4200 routers.
Sante Report - The
Zero Day Initiative published a report
that describes a buffer overflow vulnerability in the Sante DICOM Viewer Pro.
Solax Report - SEC
Consult published a report that describes three vulnerabilities (with
proof-of-concept code) in the Solax Power Pocket WiFi models.
Exploits
FortiGuard Exploit -
Peter Gabaldon published an exploit for an exposure of sensitive information to
an unauthorized actor vulnerability in the FortiGuard FortiGate product.
Palo Alto Networks
Exploit - Indoushka published an exploit for four vulnerabilities in the
Palo Alto Networks PAN-OS products.
For more information about these disclosures, see my article at CFSN
Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-2-c98
- subscription required.