Rewterz
Rewterz Threat Alert – Zeppelin Ransomware Targets Healthcare and IT Companies
December 12, 2019
Rewterz
Rewterz Threat Advisory – ICS: Omron PLC CJ and CS Series Multiple Vulnerabilities
December 13, 2019

Rewterz threat Advisory – CVE-2019-18257 – Advantech DiagAnywhere Server Remote Code Execution Vulnerability

Severity

High

Analysis Summary

Multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

Impact

Remote code execution

Affected Vendors

Advantech

Affected Products

DiagAnywhere Server Versions 3.07.11 and prior

Remediation

Advantech has released Version 3.07.14 of DiagAnywhere Server.

To download software update: DiagAnywhere Server update