CVE-2025-13824
A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red
CVSS
—
Sin CVSS
EPSS
0.3%
p28
KEV
—
Exploit Today
8
0-100
Publicado: 15 dic 2025 · Última mod.: 3 sept 2026 · CWE-763
0.3%EPSS · 30 días0.3%
2026-08-182026-09-15
A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-775007.8 ALT26.6%
——8Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.8dCVE-2026-748608.5 ALT28.8%
——9A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.6dCVE-2026-16005—0.5%
——0Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the '
Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.8dCVE-2026-841318.8 ALT25.9%
——8Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.13dCVE-2023-205116.4 MED14.3%
——4Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.13dCVE-2026-19315—38.6%
——12A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.13d