Rewterz

Rewterz Threat Alert – Zeppelin Ransomware Targets Healthcare and IT Companies

December 12, 2019
Rewterz

Rewterz Threat Advisory – ICS: Omron PLC CJ and CS Series Multiple Vulnerabilities

December 13, 2019

Rewterz threat Advisory – CVE-2019-18257 – Advantech DiagAnywhere Server Remote Code Execution Vulnerability

Severity

High

Analysis Summary

Multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with the privileges of the user running DiagAnywhere Server.

Impact

Remote code execution

Affected Vendors

Advantech

Affected Products

DiagAnywhere Server Versions 3.07.11 and prior

Remediation

Advantech has released Version 3.07.14 of DiagAnywhere Server.

To download software update: DiagAnywhere Server update

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.