πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-37550 β€Ό

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546,Γ‚ CVE-2023-37547, CVE-2023-37548 and CVE-2023-37549.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37555 β€Ό

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different toΓ‚ CVE-2023-37552,Γ‚ CVE-2023-37553,Γ‚ CVE-2023-37554 andΓ‚ CVE-2023-37556.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37557 β€Ό

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37549 β€Ό

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546,Γ‚ CVE-2023-37547, CVE-2023-37548 and CVE-2023-37550

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37548 β€Ό

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546,Γ‚ CVE-2023-37547, CVE-2023-37549 and CVE-2023-37550

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-4046 β€Ό

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37553 β€Ό

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different toΓ‚ CVE-2023-37552,Γ‚ CVE-2023-37554,Γ‚ CVE-2023-37555 andΓ‚ CVE-2023-37556.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37554 β€Ό

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different toΓ‚ CVE-2023-37552,Γ‚ CVE-2023-37553, CVE-2023-37555 andΓ‚ CVE-2023-37556.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37558 β€Ό

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22317 β€Ό

Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37547 β€Ό

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37546, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37551 β€Ό

In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3669 β€Ό

A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22314 β€Ό

Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37552 β€Ό

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37553,Γ‚ CVE-2023-37554,Γ‚ CVE-2023-37555 andΓ‚ CVE-2023-37556.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37559 β€Ό

After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37558

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37546 β€Ό

In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37545, CVE-2023-37547, CVE-2023-37548, CVE-2023-37549 and CVE-2023-37550

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37556 β€Ό

In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different toΓ‚ CVE-2023-37552,Γ‚ CVE-2023-37553,Γ‚ CVE-2023-37554 and CVE-2023-37555.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Lynis Auditing Tool 3.0.9 πŸ› 

Lynis is an auditing tool for Unix (specialists). It scans the system and available software to detect security issues. Beside security related information it will also scan for general system information, installed packages and configuration mistakes. This software aims in assisting automated auditing, software patch management, vulnerability and malware scanning of Unix based systems.

πŸ“– Read

via "Packet Storm Security".
πŸ“’ Top 12 most-exploited security vulnerabilities revealed by national cyber security agencies πŸ“’

Cyber leaders from the Five Eyes alliance said attackers favor older vulnerabilities rather than new ones

πŸ“– Read

via "ITPro".
πŸ•΄ Russia's 'Midnight Blizzard' Hackers Launch Flurry of Microsoft Teams Attacks πŸ•΄

The Nobelium APT is launching highly targeted Teams-based phishing attacks on government and industrial targets using compromised Microsoft 365 tenants, with the aim of data theft and cyber espionage.

πŸ“– Read

via "Dark Reading".