CISA Adds Six Known Exploited Vulnerabilities to Catalog

  • Post author:
  • Post category:

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2023-38203 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability CVE-2023-29300 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability CVE-2023-27524 Apache Superset Insecure Default Initialization of Resource Vulnerability CVE-2023-41990 Apple Multiple Products Code Execution Vulnerability CVE-2016-20017 D-Link DSL-2750B Devices Command Injection Vulnerability CVE-2023-23752 Joomla! Improper Access Control

Continue ReadingCISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA Releases Three Industrial Control Systems Advisories

  • Post author:
  • Post category:

CISA released three Industrial Control Systems (ICS) advisories on January 4, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-004-01 Rockwell Automation FactoryTalk Activation ICSA-24-004-02 Mitsubishi Electric Factory Automation Products ICSA-23-348-15 Unitronics Vision and Samba Series (Update A) CISA encourages users and administrators to review the newly released

Continue ReadingCISA Releases Three Industrial Control Systems Advisories

ICS Advisory: Mitsubishi Electric Factory Automation Products

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.5 ATTENTION: Exploitable remotely/low attack complexity Vendor: Mitsubishi Electric Equipment: Multiple Factory Automation Products Vulnerabilities: Observable Timing Discrepancy, Double Free, Access of Resource Using Incompatible Type ('Type Confusion') 2. RISK EVALUATION Successful exploitation of these vulnerabilities could disclose information in the product or could cause denial-of-service (DoS) condition.

Continue ReadingICS Advisory: Mitsubishi Electric Factory Automation Products

ICS Advisory: Rockwell Automation FactoryTalk Activation

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: FactoryTalk Activation Manager Vulnerabilities: Out-of-Bounds Write 2. RISK EVALUATION Successful exploitation of these vulnerabilities could result in a buffer overflow and allow the attacker to gain full access to the system. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The

Continue ReadingICS Advisory: Rockwell Automation FactoryTalk Activation

Empowering workplaces: EU-OSHA guides companies in safety and health compliance

  • Post author:
  • Post category:

Search Search , Occupational safety and health (OSH) regulations are not just  a set of rules ; they have the power  to  save lives and boost productivity.  EU-OSHA’s ongoing research project is  dedicated to helping companies, including micro and small enterprises (MSEs), meet these requirements and  prioritise worker wellbeing. It explores supply chains across industries

Continue ReadingEmpowering workplaces: EU-OSHA guides companies in safety and health compliance