ICS Advisory: Crestron AM-300

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.4 ATTENTION: Low attack complexity Vendor: Crestron Equipment: AM-300 Vulnerability: OS Command Injection 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to escalate their privileges to root-level access. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The following Crestron AirMedia Presentation System products are affected: AM-300:

Continue ReadingICS Advisory: Crestron AM-300

ICS Advisory: APsystems Energy Communication Unit (ECU-C) Power Control Software

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.8 ATTENTION: Exploitable via adjacent network / low attack complexity Vendor: APsystems Equipment: Energy communication Unit (ECU-C) Power Control Software Vulnerability: Improper Access Control 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to access sensitive data and execute specific commands and functions with full

Continue ReadingICS Advisory: APsystems Energy Communication Unit (ECU-C) Power Control Software

Apple Releases Security Updates for Multiple Products

  • Post author:
  • Post category:

An official website of the United States government Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure

Continue ReadingApple Releases Security Updates for Multiple Products

CISA Adds One Known Exploited Vulnerability to Catalog

  • Post author:
  • Post category:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-23222 Apple Multiple Products Type Confusion Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited

Continue ReadingCISA Adds One Known Exploited Vulnerability to Catalog

In celebration of International Data Protection Day, ANPD and CERT.br launch new publications

  • Post author:
  • Post category:

Por ocasião do Dia Internacional da Proteção de Dados, celebrado globalmente em 28 de janeiro, o Centro de Estudos, Resposta e Tratamento de Incidentes de Segurança no Brasil (CERT.br) lança dois novos fascículos da Cartilha de Segurança para Internet , cujos temas são “Proteção de Dados” e “Vazamento de Dados”. As publicações, que contam com

Continue ReadingIn celebration of International Data Protection Day, ANPD and CERT.br launch new publications