Search
Close this search box.

Vulnerability Pulse

Every week, we catalog the major industrial cybersecurity vulnerabilities and updates you should know about. Here are the notable threats from the week of October 15 - 21. Sign up to get these updates right to your inbox!

OCTOBER 19, 2023

Hitachi Energy’s RTU500 Series Product (Update B)

Hitachi Energy’s RTU500 Series Product (Update B) contains out-of-bounds read, infinite loop, classic buffer overflow and more vulnerabilities that can allow an attacker to crash the device being accessed or cause a denial-of-service condition.


Sources: CISA, Hitachi Energy

OCTOBER 18, 2023

Cisco IOS XE Web UI

Cisco IOS XE Web UI contains a privilege escalation vulnerability that can allow a remote, unauthenticated attacker to create an account with privilege level 15 access.

Sources: CISA, NIST

Citrix NetScaler ADC and NetScaler 

Citrix NetScaler ADC and NetScaler contain gateway duffer overflow vulnerabilities that can allow for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

Sources: CISA, NIST

OCTOBER 17, 2023

Schneider Electric EcoStruxure Power Monitoring Expert and Power Operation Products

Schneider Electric EcoStruxure Power Monitoring Expert and Power Operation products contain a deserialization of untrusted data vulnerability that can allow an attacker to achieve remote code execution.


Sources: CISA, Schneider Electric

Rockwell Automation FactoryTalk Linx

Rockwell Automation FactoryTalk Linx contains an improper input validation vulnerability that can lead to information disclosure or a denial-of-service condition.


Sources: CISA, Rockwell Automation

SUBSCRIBE

GET ON THE BEAT

 

Keep your finger on the pulse of top industry news

RECENT NEWS
HACKS & ATTACKS
RESOURCES