ICS Advisory: Mitsubishi Electric MELSEC-F Series

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.1 ATTENTION: Exploitable remotely/low attack complexity Vendor: Mitsubishi Electric Corporation Equipment: MELSEC-F Series Vulnerability: Improper Authentication 2. RISK EVALUATION Successful exploitation of this vulnerability may allow a remote attacker to obtain sequence programs from the product, write malicious sequence programs, or improper data in the product without authentication.

Continue ReadingICS Advisory: Mitsubishi Electric MELSEC-F Series

US Department of Labor enters agreement with B. Braun Medical after gender-based hiring discrimination continued at its Allentown location

  • Post author:
  • Post category:

ALLENTOWN, PA – The U.S. Department of Labor Office of Federal Contract Compliance Programs has entered into a conciliation with B. Braun Medical Inc., to resolve allegations that the federal contractor breached a 2020 agreement to address discrimination against female employees and applicants at its Allentown manufacturing facility.An OFCCP review of progress reports provided by the company

Continue ReadingUS Department of Labor enters agreement with B. Braun Medical after gender-based hiring discrimination continued at its Allentown location

ICS Advisory: Weintek cMT3000 HMI Web CGI

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Weintek Equipment: cMT3000 CMI Web CGI Vulnerabilities: Stack-based Buffer Overflow, OS Command Injection 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to hijack control flow and bypass login authentication or execute arbitrary commands. 3. TECHNICAL DETAILS 3.1

Continue ReadingICS Advisory: Weintek cMT3000 HMI Web CGI

Federal investigation into workplace fatality finds Tulsa metal fabrication company exposed employees to dozens of safety, health hazards

  • Post author:
  • Post category:

TULSA, OK – Three federal workplace safety and health investigations that followed the April 2023 death of a worker at a Tulsa manufacturing facility found the company exposed employees to struck-by hazards and identified 36 violations, including 25 serious safety violations of U.S. Department of Labor regulations. Investigators with the department’s Occupational Safety and Health Administration opened

Continue ReadingFederal investigation into workplace fatality finds Tulsa metal fabrication company exposed employees to dozens of safety, health hazards

ICS Advisory: Siemens Mendix Forgot Password Module

  • Post author:
  • Post category:

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global). View CSAF 1. EXECUTIVE SUMMARY CVSS v3 5.3 ATTENTION: Exploitable remotely/low attack

Continue ReadingICS Advisory: Siemens Mendix Forgot Password Module