Rewterz

Rewterz Threat Advisory – CVE-2020-3382 – Critical Vulnerabilities in Cisco’s DCNM and SD-WAN vManage software

July 30, 2020
Rewterz

Rewterz Threat Alert – GuLoader Resurfaces in a Malspam Campaign

August 3, 2020

Rewterz Threat Advisory – CVE-2020-14520 – ICS: Inductive Automation Ignition 8

Severity

Medium

Analysis Summary

The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information. An HTTP request to the unprotected API could be used to determine whether an arbitrary file path exists on the filesystem. No authentication is required to perform this exploit.

Impact

Access to sensitive information

Affected Vendors

Inductive Automation

Affected Products

Inductive Automation Ignition 8 All versions prior to 8.0.13

Remediation

Inductive Automation recommends users upgrade the Ignition software to v8.0.13

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.