Rewterz

Rewterz Threat Alert – Emotet Malware – IOCs

August 24, 2020
Rewterz

Rewterz Threat Alert -Multiple Vulnerabilities In Discount Rules for WooCommerce Plugin

August 24, 2020

Rewterz Threat Advisory – CVE-2020-15781 – ICS:Siemens SICAM A8000 RTUs

Severity

Medium

Analysis Summary

The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting user views the log messages via a web browser, these log messages might be interpreted and executed as code by the web application. This cross-site scripting (XSS) vulnerability might compromise the confidentiality, integrity, and availability of the web application.

Impact

Cross-site scripting

Affected Vendors

Siemens

Affected Products

SICAM WEB firmware: all versions prior to C05.30

Remediation

Siemens recommends users update to the latest version, v05.30

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.