Search
Close this search box.

Vulnerability Pulse

Every week, we catalog the major industrial cybersecurity vulnerabilities and updates you should know about. Here are the notable threats from the week of September 25 - October 1. Sign up to get these updates right to your inbox!

SEPTEMBER 30, 2022

Microsoft Guidance on zero-day vulnerabilities

Microsoft released a guide on zero-day vulnerabilities in Microsoft Exchange Server.

Sources: Microsoft Guidance, CISA

Mozilla Thunderbird 102.3.1

Mozilla released a security update for Thunderbird due to vulnerabilities found that could lead to an attacker gaining control of affected systems.

Sources: Mozilla Thunderbird Advisory, CISA

Drupal SA-CORE-2022-016

Drupal released security updates due to vulnerabilities found in multiple versions of Drupal that could lead to an attacker obtaining sensitive information.

Sources: Drupal Security Advisory, CISA

SEPTEMBER 29, 2022

Hitachi Energy MicroSCADA Pro/X SYS600

Hitachi Energy MicroSCADA Pro/X SYS600 contains improper input validation, improper privilege management, improper access control and improper handling of unexpected data type vulnerabilities that could lead to a denial-of-service condition.

Sources: Hitachi Energy Support, CISA, Hitachi Energy Advisory

Baxter Sigma Spectrum Infusion Pump

Baxter Sigma Spectrum Infusion Pump contains missing encryption of sensitive data, use of externally controlled format string and missing authentication for critical function vulnerabilities that could lead to an attacker gaining access to sensitive data and alteration of system configuration.

Sources: Baxter Product Security Bulletin, CISA

ARC Informatique PcVue

ARC Informatique PcVue contains a cleartext storage of sensitive information vulnerability that could lead to access to the OAuth web service database.

Sources: Maintenance Release, CISA

Delta Electronics DOPSoft update A

Delta Electronics DOPSoft contains an out-of-bounds read vulnerability that could lead to an attacker obtaining sensitive information.

Sources: Delta Electronics Update, CISA

Delta Electronics DOPSoft update B

Delta Electronics DOPSoft contains an out-of-bounds read vulnerability that could lead to arbitrary code execution and disclose information.

Sources: Delta Electronics Update, CISA

VMWare, Protecting vSphere From Specialized Malware

VMWare released Protecting vSphere From Specialized Malware that explains VirtualPITA (ESXi & Linux), VirtualPIE (ESXi) and VirtualGATE (Windows).

Sources: Protecting vSphere From Specialized Malware, CISA

SEPTEMBER 27, 2022

Hitachi Energy AFS660/AFS665

Hitachi Energy AFS660/AFS665 contains an improper input validation vulnerability that could allow an attacker to overflow an internal buffer and fully compromise the target device.

Sources: Hitachi Advisory, CISA

Hitachi Energy Lumada Asset Performance Management (APM) Edge

Hitachi Energy Lumada Asset Performance Management (APM) Edge contains out-of-bounds write and improper authentication vulnerabilities that could lead to an escalation of privileges from a user account to root.

Sources: Hitachi Energy Advisory, CISA

Rockwell Automation ThinManager ThinServer

Rockwell Automation ThinManager ThinServer contains a heap-based buffer overflow vulnerability that could lead to the software crashing; a buffer overflow condition may allow remote code execution.

Sources: Rockwell Automation Security Advisory, CISA

SUBSCRIBE

GET ON THE BEAT

 

Keep your finger on the pulse of top industry news

RECENT NEWS
HACKS & ATTACKS
RESOURCES