ICS Advisory: Mitsubishi Electric MELSEC Series

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.1 ATTENTION: Exploitable remotely/low attack complexity Vendor: Mitsubishi Electric Corporation Equipment: MELSEC Series Vulnerability: Insufficient Verification of Data Authenticity 2. RISK EVALUATION Successful exploitation of this vulnerability may allow a remote attacker to reset the memory of the products to factory default state and cause a denial-of-service condition.

Continue ReadingICS Advisory: Mitsubishi Electric MELSEC Series

Federal investigation of amputation injury finds Rana Meal Solutions again failed to protect employees from machines’ moving parts

  • Post author:
  • Post category:

BARTLETT, IL – For the third time in five years, federal investigators have found a nationwide provider of ready-made pasta, sauces and meals failed to follow workplace safety requirements to prevent workers from coming into contact with moving machine parts.Inspectors with the U.S. Department of Labor’s Occupational Safety and Health Administration investigating a report by

Continue ReadingFederal investigation of amputation injury finds Rana Meal Solutions again failed to protect employees from machines’ moving parts

ICS Advisory: Mitsubishi Electric MELSEC iQ-F Series CPU Module

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 5.3 ATTENTION: Exploitable remotely/low attack complexity Equipment: MELSEC iQ-F Series Vulnerability: Improper Restriction of Excessive Authentication Attempts 2. RISK EVALUATION Successful exploitation of this vulnerability could allow a remote attacker to prevent legitimate users from logging into the web server function for a certain period, resulting in a

Continue ReadingICS Advisory: Mitsubishi Electric MELSEC iQ-F Series CPU Module

ICS Advisory: Red Lion Crimson

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Red Lion Equipment: FlexEdge Gateway, DA50A, DA70A running Crimson Vulnerability: Improper Neutralization of Null Byte or NUL Character 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to truncate passwords configured by the Crimson configuration tool which could

Continue ReadingICS Advisory: Red Lion Crimson

Atlassian Releases Security Advisory for Confluence Data Center and Server

  • Post author:
  • Post category:

An official website of the United States government Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Cybersecurity &

Continue ReadingAtlassian Releases Security Advisory for Confluence Data Center and Server