ICS Advisory: RoboDK RoboDK

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 3.3 ATTENTION: Low attack complexity Vendor: RoboDK Equipment: RoboDK Vulnerability: Heap-based Buffer Overflow 2. RISK EVALUATION Successful exploitation of this vulnerability could result in an attacker crashing the program through heap-based buffer overflow. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The following versions of RoboDK, a robotics development software

Continue ReadingICS Advisory: RoboDK RoboDK

ICS Advisory: Rockwell Automation ControlLogix and GuardLogix

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 9.2 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, 1756-EN4TR Vulnerability: Improper Input Validation 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to cause a major nonrecoverable fault (MNRF) resulting in the product to become unavailable. 3.

Continue ReadingICS Advisory: Rockwell Automation ControlLogix and GuardLogix

ICS Advisory: Electrolink FM/DAB/TV Transmitter

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.8 ATTENTION: Exploitable remotely/low attack complexity/public exploits are available Vendor: Electrolink Equipment: FM/DAB/TV Transmitter Vulnerabilities: Authentication Bypass by Assumed-Immutable Data, Reliance on Cookies without Validation and Integrity Checking, Missing Authentication for Critical Function, Cleartext Storage of Sensitive Information 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow

Continue ReadingICS Advisory: Electrolink FM/DAB/TV Transmitter

ICS Advisory: Measuresoft ScadaPro

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 6.8 ATTENTION: Low attack complexity Vendor: Measuresoft Equipment: ScadaPro Vulnerability: Improper Access Control 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an attacker to escalate their privileges from unprivileged to SYSTEM privileges. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The following versions of ScadaPro, a supervisory control

Continue ReadingICS Advisory: Measuresoft ScadaPro

The operational guide on storage systems has been published

  • Post author:
  • Post category:

E' stata pubblicata sul sito istituzionale del Ministero dell’Ambiente e della Sicurezza energetica la “Guida operativa "per la predisposizione della documentazione per le istanze di Autorizzazione Unica dei sistemi di accumulo elettrochimico in configurazione stand alone, ai sensi del D.L. 7/2002 (art.1, comma 2 quater, lettera b) e del D.lgs. 387/2003.” La documentazione illustrata nel

Continue ReadingThe operational guide on storage systems has been published