Rewterz

Rewterz Threat Advisory – ICS: Delta Industrial Automation CNCSoft ScreenEditor

August 5, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-5616 – Multiple PHP Factory products security bypass

August 5, 2020

Rewterz Threat Advisory – CVE-2020-4631 – IBM Spectrum Protect Plus

Severity

Medium

Analysis Summary

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations.

Impact

Denial of service

Affected Vendors

IBM

Affected Products

  • IBM Spectrum Protect Plus 10.1.0
  • IBM Spectrum Protect Plus 10.1.6

Remediation

Refer to IBM Security Bulletin 6255116 for patch, upgrade or suggested workaround information.

https://www.ibm.com/support/pages/node/6255116

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.