Search
Close this search box.

Vulnerability Pulse

Every week, we catalog the major industrial cybersecurity vulnerabilities and updates you should know about. Here are the notable threats from the week of July 30 - August 5. Sign up to get these updates right to your inbox!

AUGUST 03, 2023

Mitsubishi Electric GOT2000 and GOT SIMPLE

Mitsubishi Electric GOT2000 and GOT SIMPLE contain a predictable exact value from previous values vulnerability that can allow an attacker to hijack data connections or prevent legitimate users from establishing data connections.


Sources: CISA, Mitsubishi Electric

Mitsubishi Electric GT and GOT Series Products

Mitsubishi Electric GT and GOT Series products contain a weak encoding for password vulnerability that can allow an attacker to obtain plaintext passwords by sniffing packets containing encrypted passwords and decrypting the encrypted passwords.


Sources: CISA, Mitsubishi Electric

TEL-STER TelWin SCADA WebInterface

TEL-STER TelWin SCADA WebInterface contains a path traversal vulnerability that can allow an unauthenticated attacker to read files on the system.


Sources: CISA, TEL-STER

Sensormatic Electronics VideoEdge

Sensormatic Electronics VideoEdge contains an acceptance of extraneous untrusted data with trusted data vulnerability that can allow a local user to edit the VideoEdge configuration file and interfere with VideoEdge operation.


Sources: CISA, Sensormatic

Mitsubishi Electric CNC Series (Update A)

Mitsubishi Electric CNC Series (Update A) contains a classic buffer overflow vulnerability that can allow a malicious remote attacker to cause a denial-of-service condition and execute malicious code on the product by sending specially crafted packets.


Sources: Mitsubishi Electric, CISA

AUGUST 01, 2023

APSystems Altenergy Power Control

APSystems Altenergy Power Control contains an OS command injection vulnerability that can allow remote code execution.


Sources: CISA, APSystems

JULY 31, 2023

Ivanti Endpoint Manager Mobile 

Ivanti Endpoint Manager Mobile contains a path traversal vulnerability that can allow an authenticated administrator to perform malicious file writes to the EPMM server.

Sources: CISA, NIST

SUBSCRIBE

GET ON THE BEAT

 

Keep your finger on the pulse of top industry news

RECENT NEWS
HACKS & ATTACKS
RESOURCES