Rewterz

Rewterz Threat Advisory – ICS: Treck TCP/IP Stack Multiple Vulnerabilities

August 26, 2020
Rewterz

Rewterz Threat Alert – Phishing Campaign Targeting Pakistani Users

August 27, 2020

Rewterz Threat Advisory – ICS: CVE-2020-16235 – Emerson OpenEnterprise SCADA Software

Severity

Medium

Analysis Summary

Emerson’s OpenEnterprise SCADA software has Inadequate Encryption Strength. Successful exploitation of this vulnerability could allow an attacker access to credentials held by OpenEnterprise used for accessing field devices and external systems. This may result in security bypass.

Impact

Security Bypass

Affected Vendors

Emerson

Affected Products

OpenEnterprise All versions through 3.3.5

Remediation

Emerson recommends all users upgrade to OpenEnterprise 3.3, Service Pack 6 (3.3.6), to resolve this issue. OpenEnterprise Service Packs are available to users with access to the Emerson SupportNet system (login required).

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.