Sunday, July 20, 2025

Review – Public ICS Disclosures – Week of 7-12-25 – Part 2

For Part 2 we have 3 additional vendor disclosures from Rockwell, VMware, and Zyxel. There are 6 updated advisories from Broadcom (2), Moxa, Siemens, VMware, and Zyxel. Finally, we have 7 researcher reports about vulnerabilities in products from Zyxel, and Dassault Systems (6).

Advisories

Rockwell Advisory - Rockwell published an advisory that discusses four vulnerabilities in their Lifecycle Services with VMware product.

VMware Advisory - Broadcom published an advisory that describes four vulnerabilities in multiple VMware products.

Zyxel Advisory - Zyxel published an advisory that describes a path traversal vulnerability in multiple access point (AP) products

Updates

Broadcom Update #1 - Broadcom published an update for their ASCG Vulnerability Disclosures advisory that was originally published on January 7th, 2025, and most recently updated on June 10th, 2025. 

Broadcom Update #2 - Broadcom published an update for their AF_UNIX Module advisory that was originally published on June 10th, 2025.

Moxa Update - Moxa published an update for their EDS-508A Series advisory that was originally published on January 15th, 2025.

Siemens Update - Siemens published an update for their n SICAM TOOLBOX advisory that was originally published on July 8th, 2025.

VMware Update - Broadcom published an update for their VMware NSX advisory that was originally published on June 4th, 2025.

 Zyxel Update - Zyxel published an update for their denial-of-service vulnerabilities of CPE advisory that was originally published on December 17th, 2020 and most recently updated on January 29th, 2021.

Researcher Reports

Dassault Reports - The Zero Day Iniative published six reports of individual vulnerabilities in the Dassault Systèmes eDrawings Viewer.

Zyxel Report - Vulncheck published a report that describes a command injection vulnerability in Multiple Zyxel CPE models.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-6e6 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */