View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Critical OpenSSL Stack Buffer Overflow in Siemens Desigo CC

📋 ADVISORIES

  • Critical Stack Buffer Overflow in Siemens Desigo CC via OpenSSL Parsing (CVE-2025-15467)
    Siemens Desigo CC is vulnerable to a critical OpenSSL stack buffer overflow allowing DoS or remote code execution.

    • Applies to Siemens Desigo CC versions V7 all, V8 all, and V9 versions below 9.0.1
    • Vulnerability is a stack-based buffer overflow in OpenSSL when parsing CMS AuthEnvelopedData with AEAD ciphers like AES-GCM
    • Attack exploits oversized Initialization Vector in ASN.1 parameters causing out-of-bounds write before authentication
    • No valid key material required to trigger overflow; leads to denial of service or potential remote code execution
    • CVSS 3.1 base score 9.8 (critical); Siemens has released patches for V8 and V9, with further fixes planned
      Coverage: cisa.gov · Original: cisa.gov · via CISA Advisories
  • Apple iOS 26.6 Fixes Kernel Code Execution, Root Access, and Sandbox Escape Flaws
    Apple released iOS 26.6 to fix multiple critical vulnerabilities including kernel code execution and sandbox escapes.

    • Applies to iPhone 11 and later, and supported iPad models
    • Fixes kernel vulnerabilities enabling arbitrary code execution, root access, and sandbox escape
    • Critical flaw in AVEVideoEncoder (CVE-2026-64747) allows kernel code execution via buffer overflow
    • Other fixes include kernel memory corruption (CVE-2026-28931), root privilege escalation (CVE-2026-43723), and sandbox escapes (CVE-2026-64740, CVE-2026-28973)
    • Vulnerabilities exploitable via malicious apps, crafted files, or malicious network servers
      Coverage: cybersecuritynews.com · via Cyber Security News
  • Siemens Mendix Runtime Documentation Gap Leads to Overly Permissive Access Rules
    Siemens Mendix Runtime documentation gap causes insecure access rule configurations exposing user data.

    • Applies to Siemens Mendix Runtime versions: all versions affected
    • Vulnerability involves inadequate documentation of System.User entity access rules
    • Developers may unknowingly configure overly permissive access, exposing sensitive user data
    • Common misconfiguration allows anonymous user role to access all System.User records without explicit rights
    • Attack vector: insecure inherited permissions due to documentation gap, enabling privilege escalation
      Coverage: cisa.gov · Original: cisa.gov · via CISA Advisories
  • siemens-simatic-s7-plcsim-advanced-dosCISA Advisories

  • siemens-simatic-s7-1500-firmware-multiple-vulnerabilitiesCISA Advisories

  • abb-knx-update-tool-vulnerabilityCISA Advisories

🕵️ RESEARCH & DEEP DIVES

  • Over 24,000 Internet-Exposed BMCs Leak IPMI Password Hashes Before Login
    More than 24,000 internet-exposed BMCs leak IPMI password hashes due to a protocol flaw.

    • Applies to over 36,000 internet-exposed Baseboard Management Controllers (BMCs) running IPMI v2.0
    • 24,650 BMCs disclose password-derived authentication hashes before login, enabling offline cracking
    • Vulnerability stems from CVE-2013-4786, an inherent flaw in IPMI v2.0 allowing HMAC retrieval via UDP port 623
    • Exposed hashes include weak, factory-set, or predictable passwords recoverable with GPU-accelerated cracking
    • Affected hardware includes modern Supermicro and HPE servers used by GPU providers and AI data centers
      Coverage: thehackernews.com · via The Hacker News
  • MikroTik RouterOS and Cloud Hosted Router vulnerable to password guessing (CVE-2026-16347) CVE-2026-16347
    MikroTik RouterOS and Cloud Hosted Router allow rapid password guessing due to insufficient authentication attempt restrictions.

    • Applies to all versions of MikroTik RouterOS and Cloud Hosted Router worldwide
    • Vulnerability in API authentication lacks effective rate-limiting and account lockout
    • Attackers can perform high-volume concurrent login attempts to guess passwords
    • Exploitation could lead to unauthorized administrative access
    • No fix currently available; vulnerability scored 8.8 (CVSS v3.1) high severity
      Coverage: cisa.gov · Original: cisa.gov · via CISA Advisories
  • igloohome Smart Lock Android App Vulnerable to Unauthorized Access via Sensitive Info Exposure (CVE-2026-16581) CVE-2026-16581
    igloohome Smart Lock Mobile App versions 3.2.3 and prior expose sensitive info enabling unauthorized access.

    • Applies to igloohome Smart Lock Mobile Application for Android, version 3.2.3 and earlier
    • Vulnerability involves inclusion of sensitive information in source code accessible without authentication
    • Allows unauthorized actors to access backend functions or services lacking proper authentication controls
    • Attack vector is remote network access without user interaction, exploiting exposed sensitive data
    • CVSS v3.1 base score is 5.3 (Medium severity), CVSS v4.0 score is 6.9 (Medium severity)
      Coverage: cisa.gov · Original: cisa.gov · via CISA Advisories
  • Camaleon CMS 2.1.1-2.9.1 Authenticated RCE via select_eval Custom Field (CVE-2026-66748) CVE-2026-66748
    Camaleon CMS versions 2.1.1 to 2.9.1 have an authenticated remote code execution vulnerability.

    • Applies to Camaleon CMS versions 2.1.1 through 2.9.1
    • Allows users with custom_fields manage permission to execute arbitrary Ruby code
    • Vulnerability exploited by supplying malicious Ruby expression via select_eval custom field
    • Code executed with web server process privileges during post edit page rendering
      Coverage: cve.threatint.com · Original: cve.threatint.com · via CVE ThreatInt
  • Tengu Botnet Reboots Linux Devices to Maintain Persistence After Process Kill
    Tengu botnet reboots compromised Linux devices using hardware watchdog to maintain persistence.

    • Targets Linux devices via Telnet credential brute force attacks
    • Uses hardware watchdog to trigger reboot if main malware process is killed
    • Supports 25 DDoS methods, SOCKS5 proxy, shell commands, and system data collection
    • Employs multiple persistence methods including fake systemd services and immutable binaries
    • Communicates with C2 server at 64.89.163.8:9931 using encrypted commands and can update itself
      Coverage: thehackernews.com · Original: thehackernews.com · via The Hacker News

🔓 CVEs & KEV

  • Other: 19 CVEs (worst 8.2)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check