Sunday, May 25, 2025

Review – Public ICS Disclosures – Week of 5-17-25 – Part 2

For Part 2 we have five vendor updates from Broadcom, GE Vernova, HPE (2), and Siemens. There are also eight researcher reports for vulnerabilities in products from ABB (7) and eCharge.

Updates

Broadcom Update - Broadcom published an update for their curl/Libcurl advisory that was originally published on December 14th, 2016.

GE Vernova Update - GE published an update for their WorkstationST EGD Configuration Server advisory that was originally published on September 24th, 2024, and most recently updated on November 1st, 2024.

HPE Update #1 - HPE published an update for their ProLiant DL/ML, MicroServer, Synergy and Edgeline Servers advisory that was originally published on May 12th, 2025.

HPE Update #2 - HPE published an update for their ProLiant DL/ML/XL, Alletra, Edgeline and Synergy Servers advisory that was originally published on May 13th, 2025.

Siemens Update - Siemens published an update for their Mendix OIDC SSO Module advisory that was originally published on May 13th, 2025.

Researcher Reports

ABB Cylon BACnet Report - Zero Science published a report that describes an out-of-bounds write vulnerability in the ABB Cylon BACnet MS/TP Kernel Module.

ABB Cylon FLXeon Reports - Zero Science published six reports describing individual vulnerabilities (with publicly available exploits) in the ABB Cylon FLXeon product.

eCharge Report - SEC Consult published a report describing seven vulnerabilities in the eCharge Hardy Barth cPH2 and cPP2 charging stations.

 

For more information on these disclosures, including a summary of changes made in updates and links to exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-a55 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */