πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-23447 β€Ό

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivilegedremote attacker to influence the availability of the webserver by invocing several open file requests viathe REST interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47378 β€Ό

Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22508 β€Ό

Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block consecutive logins of a specific type.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23448 β€Ό

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows aremote attacker to gain information about valid usernames via analysis of source code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31409 β€Ό

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22684 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Subscribers.Com Subscribers plugin <=Γ‚ 1.5.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47390 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47393 β€Ό

An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23445 β€Ό

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remoteattacker to gain unauthorized access to data fields by using a therefore unpriviledged account via theREST interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47388 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47385 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47381 β€Ό

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31408 β€Ό

Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR withPartnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remoteattacker to potentially steal user credentials that are stored in the userÒ€ℒs browsers local storage viacross-site-scripting attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47391 β€Ό

In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47386 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47383 β€Ό

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47379 β€Ό

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can leadΓ‚ to a denial-of-service condition, memory overwriting, or remote code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4048 β€Ό

Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Breach at US Transportation Department exposes 240,000 employee records πŸ“’

An investigation is underway into the breach, which affected former and current employee data

πŸ“– Read

via "ITPro".
πŸ•΄ Microsoft Advisories Are Getting Worse πŸ•΄

A predictable patch cadence is nice, but the software giant can do more.

πŸ“– Read

via "Dark Reading".
πŸ•΄ TSA Official: Feds Improved Cybersecurity Response Post-Colonial Pipeline πŸ•΄

US Transportation Security Agency (TSA) administrator reflects on how the Colonial Pipeline incident has moved the needle in public-private cooperation.

πŸ“– Read

via "Dark Reading".