Saturday, September 20, 2025

Review – Public ICS Disclosures – Week of 9-13-25 – Part 1

This was a moderately busy disclosure week. For Part 1 we have 12 vendor disclosures from Dassault Systems (3), Eaton (2), Hitachi, HP (2), and HPE (4).

Advisories

Dassault Advisory #1 - Dassault published an advisory that describes the use of an uninitialized variable vulnerability in their SOLIDWORKS Desktop 2025.

Dassault Advisory #2 - Dassault published an advisory that describes a use after free vulnerability in their SOLIDWORKS Desktop 2025.

Dassault Advisory #3 - Dassault published an advisory that describes an out-of-bounds read vulnerability in their SOLIDWORKS Desktop 2025.

Eaton Advisory #1 - Eaton published an advisory that describes two path traversal vulnerabilities in their Network Cards products.

Eaton Advisory #2 - Eaton published an advisory that describes two vulnerabilities in their Rack PDU G4 products.

Hitachi Advisory - Hitachi published an advisory that discusses 46 vulnerabilities in their Disk Array products.

HP Advisory #1 - HP published an advisory that describes an OS command injection vulnerability in their HyperX NGENUITY software.

HP Advisory #2 - HP published an advisory that discusses eight vulnerabilities in multiple HP products.

HPE Advisory #1 - HPE published an advisory that discusses 13 vulnerabilities (five with publicly available exploits) in their Telco Intelligent Assurance product.

HPE Advisory #2 - HPE published an advisory that describes a cross-site scripting vulnerability in their Aruba ClearPass Policy Manager.

HPE Advisory #3 - HPE published an advisory that discusses three vulnerabilities in their Telco Service Activator product.

HPE Advisory #4 - HPE published an advisory that describes nine vulnerabilities in their Aruba Networking EdgeConnect SD-WAN Gateways.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-403 - subscription required

No comments:

 
/* Use this with templates/template-twocol.html */