logo

“Good enough” emulation: Fuzzing a single thread to uncover vulnerabilities

ID: 3db4f253-450a-593d-8932-774e84453f14

STIX ID: report--3db4f253-450a-593d-8932-774e84453f14

Feed Name: Cisco Talos

Threat Score
55/100

Date Published: 2026-02-18

Date Updated: 2026-04-27

Author: Kelly Patterson

...
...

This Cisco Talos research report describes how the author bypassed hardware code read-out protection by emulating only the Modbus-processing thread of a Socomec DIRIS M-70 gateway using Unicorn (with AFL) and Qiling to fuzz and analyze Modbus handling, which uncovered six DoS vulnerabilities (several CVEs) that were responsibly disclosed and patched by the vendor; the write-up outlines the emulation/fuzzing workflow, tooling choices, triage steps, and recommends Qiling for future single-thread emulation projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.