Rewterz

Rewterz Threat Advisory – CVE-2020-6284 – SAP Netweaver (Knowledge Management) Cross-Site Scripting (XSS) vulnerability

August 12, 2020
Rewterz

Rewterz Threat Alert – Script-Based Malware through Internet Explorer Exploits

August 13, 2020

Rewterz Threat Advisory – CVE-2020-10055 – ICS: Siemens Desigo CC

Severity

High

Analysis Summary

Affected applications are delivered with a third-party component that contains a remote code execution vulnerability if the advanced reporting engine is enabled.

Impact

Code Injection

Affected Vendors

Siemens

Affected Products

  • Desigo CC: Versions 3.x and 4.x
  • Desigo CC Compact: Versions 3.x and 4.x

Remediation

Siemens has released patches for the affected products and recommends users to update to latest patch.

Users of Version 4.x, apply the latest patch
Users of Version 3.x, apply the latest patch

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.