Search
Close this search box.

Vulnerability Pulse

Every week, we catalog the major industrial cybersecurity vulnerabilities and updates you should know about. Here are the notable threats from the week of March 19 - 25. Sign up to get these updates right to your inbox!

MARCH 23, 2023

RoboDK

RoboDK contains an incorrect permission assignment for critical resource vulnerability that could allow an attacker to escalate privileges and write files to the RoboDK directory.


Sources: CISA, RoboDK

CP Plus KVMS Pro

CP Plus KVMS Pro contains an insufficiently protected credentials vulnerability that could allow an attacker to retrieve sensitive credentials and control the entire CCTV system.


Sources: CISA, CP Plus

SAUTER EY-modulo 5 Building Automation Stations

SAUTER EY-modulo 5 Building Automation Stations contain cross-site scripting, cleartext transmission of sensitive information and unrestricted upload of file with dangerous type vulnerabilities that can lead to privilege escalation, unauthorized execution of actions or a denial-of-service condition.


Sources: CISA, SAUTER

Schneider Electric IGSS

Schneider Electric IGSS contains missing authentication for critical function, insufficient verification of data authenticity, deserialization of untrusted data and more vulnerabilities that can result in a denial-of-service condition, as well as modification of dashboards or report files in the IGSS Report folder.


Sources: CISA, Schneider Electric

ABB Pulsar Plus Controller

ABB Pulsar Plus Controller contains use of insufficiently random values and cross-site request forgery vulnerabilities that could allow an attacker to take control of the product or execute arbitrary code.


Sources: CISA, ABB

ProPump and Controls Osprey Pump Controller

ProPump and Controls Osprey Pump Controller contains insufficient entropy, use of hard-coded password, OS command injection and more vulnerabilities that could allow an attacker to gain unauthorized access, retrieve sensitive information, modify data or cause a denial-of-service condition.


Sources: CISA, Pro Pump and Controls

MARCH 21, 2023

Keysight N6845A Geolocation Server

Keysight N6845A Geolocation Server contains a deserialization of untrusted data vulnerability that could allow an attacker to escalate privileges in the affected device’s default configuration, resulting in remote code execution.

Sources: CISA, Keysight

Delta Electronics InfraSuite Device Master

Delta Electronics InfraSuite Device Master contains path traversal, improper authentication, command injection and more vulnerabilities that could allow an unauthenticated attacker to obtain access to files and credentials, escalate privileges and remotely execute arbitrary code.


Sources: CISA, Delta Electronics

Siemens RADIUS Client of SIPROTEC 5 Devices

Siemens RADIUS Client of SIPROTEC 5 Devices contains a loop with unreachable exit condition vulnerability that could be triggered when a specially crafted packet is sent by a RADIUS server.


Sources: CISA, Siemens

VISAM VBASE Automation Base

VISAM VBASE Automation Base contains an improper restriction of XML external entity reference vulnerability that could allow an attacker to obtain sensitive information from the target device.


Sources: CISA, VBASE

Rockwell Automation ThinManager

Rockwell Automation ThinManager contains path traversal and heap-based buffer overflow vulnerabilities that could allow an attacker to potentially perform remote code execution on the target system/device or crash the software.


Sources: CISA, Rockwell Automation

Siemens SCALANCE Third-Party

Siemens SCALANCE Third-Party contains out-of-bounds write, NULL pointer dereference, out-of-bounds read and more vulnerabilities that could allow an attacker to cause a denial-of-service condition or disclose sensitive data.


Sources: CISA, Siemens

Hitachi Energy GMS600, PWC600 and Relion

Hitachi Energy GMS600, PWC600 and Relion contain an improper access controls vulnerability that could allow an attacker with user credentials to bypass security controls enforced by the product.


Sources: CISA, Hitachi Energy

SUBSCRIBE

GET ON THE BEAT

 

Keep your finger on the pulse of top industry news

RECENT NEWS
HACKS & ATTACKS
RESOURCES