“Good enough” emulation: Fuzzing a single thread to uncover vulnerabilities
ID: 3db4f253-450a-593d-8932-774e84453f14
STIX ID: report--3db4f253-450a-593d-8932-774e84453f14
Feed Name: Cisco Talos
This Cisco Talos research report describes how the author bypassed hardware code read-out protection by emulating only the Modbus-processing thread of a Socomec DIRIS M-70 gateway using Unicorn (with AFL) and Qiling to fuzz and analyze Modbus handling, which uncovered six DoS vulnerabilities (several CVEs) that were responsibly disclosed and patched by the vendor; the write-up outlines the emulation/fuzzing workflow, tooling choices, triage steps, and recommends Qiling for future single-thread emulation projects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
