IT Professionals Think They’re Better Than Their Security

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2018-7790
PUBLISHED: 2018-08-29

An Information Management Error vulnerability exists in Schneider Electric’s Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Mo…

CVE-2018-7791
PUBLISHED: 2018-08-29

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric’s Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this …

CVE-2018-7792
PUBLISHED: 2018-08-29

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric’s Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

CVE-2018-12240
PUBLISHED: 2018-08-29

The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.

CVE-2018-7789
PUBLISHED: 2018-08-29

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric’s Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.

Read More HERE

Leave a Reply