Showing posts with label Eclipse. Show all posts
Showing posts with label Eclipse. Show all posts

Sunday, August 3, 2025

Review – Public ICS Disclosures – Week of 7-26-25 – Part 2

For Part 2 this week we have an additional vendor disclosure from HPE. There are also four vendor updates from Broadcom, and HP (3). We also have 35 researcher reports for vulnerabilities in products from Eclipse, Ilevia (2), MedDream (4), QNAP (26), and Tesla (2). Finally, we have two exploits for products from AK-Nord and Helmholz.

Advisories

HPE Advisory - HPE published an advisory that discusses 12 vulnerabilities in their Telco Network Function Virtual Orchestrator product.

Updates

Broadcom Update - Broadcom published an update for their GNU Glibc advisory that was originally published on July 8th, 2025.

HP Update #1 - HP published an update for their Intel 2025.1 IPU Chipset advisory that was originally published on March 10th, 2025.

HP Update #2 - HP published an update for their UEFI Firmware advisory that was originally published on February 3rd, 2022, and most recently updated on May 28th, 2025.

HP Update #3 - HP published an update for their Intel PROSet/Wireless WiFi advisory that was originally published on March 13th, 2025, and most recently updated on July 11th, 2025.

Researcher Reports

Eclipse Report - Cisco Talos published a report about a buffer overflow vulnerability in the Eclipse ThreadX FileX RAM disk driver.

Ilevia Reports - Zero Science published two reports about vulnerabilities in the Ilevia EVE X1 Server. The report includes a link to exploit code.

MedDream Reports - Cisco Talos published four reports of vulnerabilities in the MedDream PACS Premium product. The reports include proof-of-concept code.

QNAP Reports #1 - ZDI published three reports about vulnerabilities in the QNAP TS-464 Samba.

QNAP Reports #2 - ZDI published 15 reports about vulnerabilities in the QNAP QHora-322 product.

QNAP Reports #3 - ZDI published 8 reports about vulnerabilities in the QNAP TS-464 product.

Tesla Reports - ZDI published two reports about vulnerabilities in the Tesla Wall Connector product.

Exploits

AK-Nord Exploit - Marcus Krüppel published an exploit for an insecure permissions vulnerability in the AK-Nord USB-Server-LXL Firmware.

Helmholz Exploit - M. Kadlec et al published an exploit for nine vulnerabilities in the Helmholz REX100 industrial router.

 

For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-7-782 - subscription required.

Saturday, April 19, 2025

Review – Public ICS Disclosures – Week of 4-12-25

This week we have 14 vendor disclosures from ads-tech, Broadcom, Delta Electronics, GE Vernova (2), HP, HPE (2), Philips, Rockwell Automation, SEL (3), and WAGO. There are two vendor updates from Broadcom and Siemens. We also have three researcher reports for vulnerabilities in products from Eclipse. Finally, we have two exploits for products from Ruckus and FortiGuard.

Advisories

Ads-tech Advisory - CERT-VDE published an advisory that discusses three vulnerabilities (two with publicly available exploits) in the ads-tech IRF products.

Broadcom Advisory - Broadcom published an advisory that describes an input validation vulnerability in multiple Brocade products.

Delta Advisory - Delta published an advisory that describes three vulnerabilities in their ISPsoft product.

GE Advisory #1 - GE Vernova published an advisory that discusses four vulnerabilities in their NetworkST4 devices and Remote Operations Offering products.

GE Advisory #2 - GE Vernova published an advisory that discusses three vulnerabilities (all three listed in CISA’s KEV catalog) in unspecified GE products.

HP Advisory - HP published an advisory that describes a link following vulnerability in their Touchpoint Analytics Service.

HPE Advisory #1 - HPE published an advisory that describes an unauthorized access vulnerability in their Performance Cluster Manager.

HPE Advisory #2 - HPE published an advisory that describes an unauthorized access vulnerability in their Cray Data Virtualization Service.

Philips Advisory - Philips published an advisory that discusses a use after free vulnerability (with publicly available exploit) in multiple Philips products.

Rockwell Advisory - Rockwell published an advisory that describes two vulnerabilities in their ThinManager product.

SEL Advisory #1 - SEL published a software update notice that includes cybersecurity enhancements for their SEL-5032 acSELerator Architect Software.

SEL Advisory #2 - SEL published a software update notice that includes cybersecurity enhancements for their SEL-5702 Synchrowave Operations product.

SEL Advisory #3 - SEL published a software update notice that includes cybersecurity enhancements for their SEL-5231 SEL Configuration API.

WAGO Advisory - CERT-VDE published an advisory that discusses the Year 2038 problem.

Updates

Broadcom Update - Broadcom published an update for their Fabric OS advisory that was originally published on September 26th, 2034, and most recently updated on February 27th, 2025.

Siemens Update - Siemens published an update for their Industrial Edge Device Kit advisory that was originally published on April 8th, 2025.

Researcher Reports

Eclipse Reports - Cisco Talos published three reports about individual vulnerabilities in the Eclipse ThreadX NetX Duo HTTP server.

Exploits

Ruckus Exploit - Korelogic published an exploit for an undocumented backdoor vulnerability in the Ruckus IoT Controller.

FortiGuard Exploit - Zach Hanley published a Metasploit module for an improper authentication vulnerability (listed in CISA’s KEV catalog) in multiple FortiGuard products.

 

For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-4-971 - subscription required.

 
/* Use this with templates/template-twocol.html */