Sunday, October 5, 2025

Review – Public ICS Disclosures – Week of 9-27-25 – Part 2

For Part 2 we have nine additional vendor disclosures from Dell, HPE, QNAP (4), Rockwell Automation, and VMware (2). There are three vendor updates from Hitachi Energy, HP, and Phoenix Contact.

Advisories

Dell Advisory - Dell published an advisory that discusses 22 vulnerabilities in their ThinOS 10 product. These are third-party vulnerabilities.

HPE Advisory - HPE published an advisory that discusses four vulnerabilities (two with publicly available exploits) in their Telco Service Orchestrator.

QNAP Advisory #1 - QNAP published an advisory that describes an improper authentication vulnerability in their Authenticator product.

QNAP Advisory #2 - QNAP published an advisory that describes an SQL injection vulnerability in their Video Station product.

QNAP Advisory #3 - QNAP published an advisory that describes 10 vulnerabilities in their Qsync Central product.

QNAP Advisory #4 - QNAP published an advisory that describes an unquoted search path element vulnerability in their NetBak Replicator product.

Rockwell Advisory - Rockwell published an advisory that discusses a stack-based buffer overflow vulnerability in their Lifecycle Services products.

VMware Advisory #1 - Broadcom published an advisory that describes three vulnerabilities in the VMware VMware vCenter and NSX products.

VMware Advisory #2 - Broadcom published an advisory that describes three vulnerabilities (one with publicly available exploit) in the VMware Aria Operations and VMware Tools products.

Updates

Hitachi Energy Update - Hitachi Energy published an update for their MACH SCM advisory that was originally published on March 26th, 2024.

HP Update - HP published an update for their Intel Processor Stream Cache advisory that was originally published on August 13th, 2025.

Phoenix Contact Update - CERT-VDE published an update for the Phoenix Contact Meltdown and Spectre vulnerabilities advisory that was originally published on March 23rd, 2018.

 

For more information on these disclosures, including links to 3rd party advisories and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-9-412 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */