Public ICS Disclosures – Week of 8-23-25 – Part 1
This week is a moderately busy disclosure week. We have bulk vendor disclosures from QNAP (11). We have 8 additional vendor disclosures from Cisco, Delta Electronics, Hitachi, Hitachi Energy (2), HPE (2), and Moxa.
Bulk Vendor Disclosures
QNAP Advisories
Cisco Advisory
Cisco published an advisory that describes an open redirect vulnerability in their Virtual Keyboard Video Monitor. Cisco has new versions that mitigate the vulnerability.
Delta Advisory
Delta published an advisory that describes an improper restriction of XML external entity reference vulnerability in their EIP Builder. Delta has a new version that mitigates the vulnerability.
Hitachi Advisory –
Hitachi published an advisory that discusses five vulnerabilities in multiple Hitachi products. These are third-party (Oracle) vulnerabilities. Hitachi has new versions for some of the affected products, other fixes are pending.
The five reported vulnerabilities are:
Improper access control (4) - CVE-2025-30749, CVE-2025-30754, CVE-2025-50059, and CVE-2025-50106, and
Deserialization of untrusted data - CVE-2025-30761
NOTE: It would appear that some of these vulnerabilities are actually 4th party vulnerabilities as the advisory recommends upgrading the Amazon Corretto product as part of the mitigation effort.
Hitachi Energy Advisories
Hitachi published an advisory that discusses a JAVA deserialization vulnerability in their Service Suite Product. This is a third-party (Oracle) vulnerability with a publicly available exploit, and it is listed in CISA’s Known Exploited Vulnerabilities catalog. Hitachi Energy has a new version that mitigates the vulnerability.
Hitachi published an advisory that discusses six vulnerabilities in their Asset Suite product. These are third-party vulnerabilities. Hitachi Energy has new versions that mitigate the vulnerabilities.
The six reported vulnerabilities are:
Server-side request forgery - CVE-2022-44729,
Deserialization of untrusted data - CVE-2023-6378,
Cleartext storage of sensitive information - CVE-2022-45868 (exploit),
Uncontrolled resource consumption - CVE-2025-23184,
Open redirect - CVE-2024-22262, and
Improper authentication - CVE-2022-41678 (exploit)
HPE Advisories
HPE published an advisory that discusses two vulnerabilities in their HP-UX PAM RADIUS product. These are third-party vulnerabilities. HPE has a new version that mitigates the vulnerability.
The two reported vulnerabilities are:
Out-of-bounds write - CVE-2015-9542, and
Improper validation of integrity check value - CVE-2024-3596 (exploit)
HPE published an advisory that discusses three vulnerabilities in their Compute Scale-up Server 3200 Platform Servers. These are third-party (Intel) vulnerabilities. HPE has a new version that mitigates the vulnerability.
The three reported vulnerabilities are:
Missing reference to active allocated resource - CVE-2025-21090,
Insufficient flow control management - CVE-2025-24305, and
Improper restriction of operations within the bounds of a memory buffer - CVE-2025-20053
Moxa Advisory
Moxa published an advisory that describes an unquoted search path vulnerability in the Moxa Industrial Computers. The vulnerability was reported by Anni Tuulinen. Moxa has new versions and patches that mitigate the vulnerability.