Rewterz

Rewterz Threat Alert – Fake Security Advisory used in cPanel Phishing Attack

August 11, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-8597 – ICS: Siemens SCALANCE, RUGGEDCOM

August 12, 2020

Rewterz Threat Advisory – ICS: Schneider Electric APC Easy UPS On-Line

Severity

High

Analysis Summary

CVE-2020-7521 

A vulnerability exists when accessing a vulnerable method of `FileUploadServlet` that may lead to uploading executable files to non-specified directories. 

CVE-2020-7522

A vulnerability exists when accessing a vulnerable method of `SoundUploadServlet` that may lead to uploading executable files to non-specified directories.

Impact

Remote code execution

Affected Vendors

Schneider Electric

Affected Products

SFAPV9601 v2.0 and earlier

Remediation

Schneider Electric recommends users of versions below v2.1 to update to the latest version

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.