Search
Close this search box.

Vulnerability Pulse

Every week, we catalog the major industrial cybersecurity vulnerabilities and updates you should know about. Here are the notable threats from the week of December 31 - January 6. Sign up to get these updates right to your inbox!

JANUARY 04, 2024

Rockwell Automation FactoryTalk Activation

Rockwell Automation FactoryTalk Activation contains an out-of-bounds write vulnerability that can result in a buffer overflow and allow the attacker to gain full access to the system.


Sources: CISA, Rockwell Automation

Mitsubishi Electric Factory Automation Products

Mitsubishi Electric Factory Automation products contain observable timing discrepancy, double free and access of resource using incompatible type vulnerabilities that can disclose information in the product or  cause a denial-of-service (DoS) condition.


Sources: CISA, Mitsubishi Electric

Unitronics Vision and Samba Series (Update A)

Unitronics Vision and Samba series (Update A) contain an initialization of a resource with an insecure default vulnerability that can allow an unauthenticated attacker to take administrative control of Unitronics Vision and Samba series systems and use a default administrative password.


Sources: CISA, Unitronics

JANUARY 03, 2024

Google Chromium WebRTC

Google Chromium WebRTC contains a heap buffer overflow vulnerability that can allow an attacker to cause crashes or code execution.

Sources: CISA, NIST

ParseExcel

ParseExcel contains a remote code execution vulnerability that can result in an arbitrary code execution.

Sources: CISA, NIST

SUBSCRIBE

GET ON THE BEAT

 

Keep your finger on the pulse of top industry news

RECENT NEWS
HACKS & ATTACKS
RESOURCES