UltraVNC revision 1198 contains multiple memory leaks (CWE-655) in VNC client code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another...
An attacker without authentication can login with default credentials for privileged users.
Critical vulnerabilities in industrial PCs used by Emerson’s DeltaV distributed control system could allow arbitrary code execution, malware injection or malware propagation to other workstations
UltraVNC Viewer before 1.2.2.4 has a out-of-bounds read vulnerability in RRE decoder code, caused by multiplication overflow.
New vulnerabilities have been identified in Schneider Electric PM5560 power meter and Modicon M221 logic controller
UltraVNC Viewer before 1.2.2.4 has an out-of-bounds read vulnerability inside client CoRRE decoder, caused by multiplication overflow.
The vulnerability affects PAC Control Basic and PAC Control Professional version R10.0а and earlier and could allow arbitrary code execution
UltraVNC before 1.2.2.4 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution.
USB media infected with malware were shipped with Conext ComBox and Conext Battery Monitor products
The paper provides an analysis of the prevalence of remote administration tools on OT networks and the threats associated with their use.
An attacker controlling a device with the UltraVNC Server running can perform remote code execution on the client devices to cause a denial-of-service condition, modify system's and/or obtain...
Newly identified vulnerabilities affect SIMATIC WinCC OA HMI system, SCALANCE X switches and TD Keypad Designer tool
UltraVNC before 1.2.2.4 has stack-based Buffer overflow vulnerability in VNC client code inside FileTransfer module, which leads to a denial-of-service (DoS) condition of VNC client.
Remote code execution in Emerson AMS Device Manager.
Wecon PI Studio HMI solutions are affected by multiple vulnerabilities that could allow remote code execution and disclosure of sensitive information, including in the context of an administrator
UltraVNC before 1.2.2.4 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution.
Vulnerable products include ROX II operating system, SIMATIC S7-1200 CPU family, SCALANCE W1750D access point and some SIMATIC PLCs
On March 19 2019 Norsk Hydro, one of the world’s largest aluminum producers revealed that ransomware had been used in an attack against them.
The sixth conference on industrial cybersecurity organized by Kaspersky Lab was held on September 19-21 in Sochi, Russia. This year’s theme was ‘Industrial cybersecurity: opportunities and...
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software.
Main events of the six-month period, vulnerabilities identified in 2018, relevant threats, and statistics from ICS computers protected by Kaspersky products.
User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software.
ARC Advisory Group and Kaspersky have presented a survey on the state of industrial cybersecurity in 2019
Broken access control in Moxa ThingsPro IIoT Gateway and Device Management Software.
Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software.
Successful exploitation of the vulnerabilities could allow an attacker to execute arbitrary code, crash the device or view protected data
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software.
This article continues the discussion of research on popular OEM technologies that are implemented in the products of a large number of vendors. Vulnerabilities in such technologies are highly...
Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software.
This article continues the discussion of research on popular OEM technologies that are implemented in the products of a large number of vendors. Vulnerabilities in such technologies are highly...