Saturday, July 5, 2025

Review – Public ICS Disclosures – Week of 7-28-25 – Part 1

This week we have 11 vendor disclosures from ABB, Contec, Delta Electronics, Endress+Hauser, HP (2), HPE, ifm, and Pilz (3).

Advisories

ABB Advisory - ABB published an advisory that describes four vulnerabilities in their web UI REST Interface.

Contec Advisory - Contec published an advisory that describes two vulnerabilities in their CONPROSYS HMI System.

Delta Advisory - Delta published an advisory that describes two deserialization of untrusted data vulnerabilities in their DTM Soft products.

Endress+Hauser Advisory - CERT-VDE published an advisory that discusses 19 vulnerabilities in the Endress+Hauser MEAC300-FNADE4.

HP Advisory #1 - HP published an advisory that describes a stack-based buffer overflow vulnerability in their Universal Print Driver.

HP Advisory #2 - HP published an advisory that discusses 46 vulnerabilities in their Device Manager.

HPE Advisory - HPE published an advisory that discusses a server-side request forgery vulnerability in their Telco Service Orchestrator software.

Ifm Advisory - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the ifm Smart PLC AC4xxS.

Pilz Advisory #1 - CERT-VDE published an advisory that describes an incorrect type conversion or cast vulnerability in the Pilz IndustrialPI 4 with IndustrialPI webstatus.

Pilz Advisory #2 - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the Pilz IndustrialPI 4 with Firmware Bullseye.

Pilz Advisory #3 - CERT-VDE published an advisory that discusses an authentication bypass by primary weakness vulnerability in the Pilz Software PiCtory.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-cff - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */