Rewterz

Rewterz Threat Advisory – CVE-2021-23392 – Node.js locutus module vulnerabilities

June 11, 2021
Rewterz

Rewterz Threat Advisory – Multiple Vulnerabilities of Citrix ADC and Gateway

June 11, 2021

Rewterz Threat Advisory – CVE-2021-32960 – ICS: Rockwell Automation ISaGRAF5 Runtime

Severity

High

Analysis Summary

CVE-2021-32960

FactoryTalk Services Platform contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.

Impact

  • Privilege Escalation

Affected Vendors

Rockwell Automation

Affected Products

  • FactoryTalk Services Platform v6.11 and earlier

Remediation

Refer to vendor advisory for the complete list of affected products and their respective patches at https://us-cert.cisa.gov/ics/advisories/icsa-21-161-01

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.