Rewterz

Rewterz Threat Advisory – Cisco Webex Meetings cross-site scripting

February 18, 2021
Rewterz

Rewterz Threat Advisory – ICS: Schneider Electric EcoStruxure Power Build-Rapsody

February 19, 2021

Rewterz Threat Advisory – CVE-2020-9050 – ICS: Johnson Controls Metasys Reporting Engine (MRE) Web Services

Severity

Medium

Analysis Summary

CVE-2020-9050 

Metasys Reporting Engine (MRE) Web Services does not properly sanitize pathname elements that can resolve to a location that is outside of the restricted directory.

Impact

Unauthenticated access

Affected Vendors

Johnson Controls

Affected Products

Johnson Controls MRE – v2.0
MRE – v2.1

Remediation

Johnson Controls recommends users upgrade to MRE v2.2 or later.

https://us-cert.cisa.gov/ics/advisories/icsa-21-049-01

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.