ScadaX News


Channel's geo and language: not specified, not specified
Category: not specified


https://twitter.com/ScadaXSecurity

Related channels

Channel's geo and language
not specified, not specified
Category
not specified
Statistics
Posts filter


IMPROPER RESTRICTION OF XML EXTERNAL ENTITY REFERENCE CWE-611
This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the attacker could read arbitrary files.

UNCONTROLLED RESOURCE CONSUMPTION CWE-400
This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which causes the software to quit responding until the application is restarted.

https://www.us-cert.gov/ics/advisories/icsa-19-204-01








UNRESTRICTED UPLOAD OF FILE WITH DANGEROUS TYPE CWE-434
The SIMATIC WinCC DataMonitor web application of the affected products allows an authenticated user with network access to the WinCC DataMonitor application to upload arbitrary ASPX code.
Successful exploitation requires no user interaction and may impact the confidentiality, integrity, and availability of the affected device. The vulnerability is relevant only in situations where an attacker has access via the web interface but not to the directory structure.

https://www.us-cert.gov/ics/advisories/icsa-19-192-02









9 last posts shown.

6

subscribers
Channel statistics