Saturday, August 2, 2025

Review – Public ICS Disclosures – Week of 7-26-25 – Part 1

This week we have 11 vendor disclosures from Helmholz, HP, HPE (6), MB Connect, Palo Alto Networks, and SonicWall.

 

Advisories

 

Helmholz Advisory - CERT-VDE published an advisory that describes an improper isolation or compartmentalization vulnerability in the Helmholz REX 200/250 and REX 300 products.

HP Advisory - HP published an advisory that describes an exposure of sensitive information to unauthorized actor vulnerability in their LaserJet Pro printers.

HPE Advisory #1 - HPE published an advisory that discusses 15 vulnerabilities in their HP-UX 11i v3 Tomcat-based Servlet Engine.

HPE Advisory #2 - HPE published an advisory that discusses an improper access control vulnerability in their Telco Intelligent Assurance product.

HPE Advisory #3 - HPE published an advisory that three vulnerabilities (one with publicly available exploit) in their Telco Service Activator. The first is a third-party vulnerability.

HPE Advisory #4 - HPE published an advisory that discusses 12 vulnerabilities (two with publicly available exploits) in their Telco IP Mediation product. These are third-party vulnerabilities.

HPE Advisory #5 - HPE published an advisory that discusses a use of insufficiently random values vulnerability in their Telco Service Orchestrator software.

HPE Advisory #6 - HPE published an advisory that describes ten vulnerabilities in their Private Cloud AI.

MB Connect Advisory - MB Connect published an advisory that describes an improper isolation or compartmentalization vulnerability in their mbNET/mbNET.rokey, and mbNET HW1 products.

Palo Alto Networks Advisory - PAN published an advisory that describes an incorrect privilege assignment vulnerability in their GlobalProtect App.

SonicWall Advisory - SonicWall published an advisory that discusses two vulnerabilities (one with publicly available exploit) in their SMA 100 Series Appliances.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-cd8 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */