Rewterz

Rewterz Threat Alert – Emotet Malware Steals Email Attachments to Attack Contacts

July 29, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-14498 – ICS: HMS Industrial Networks eCatcher

July 29, 2020

Rewterz Threat Advisory – ICS: Delta Industrial Automation DOPSoft

Severity

Medium

Analysis Summary

CVE-2020-10597 

Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information and/or crash the application.

CVE-2020-14482

Opening a specially crafted project file may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Impact

  • Information disclosure 
  • Application crash

Affected Vendors

Delta Electronics

Affected Products

DOPSoft Version 4.00.08.15 and prior

Remediation

Update to the latest version of DOPSoft v4.00.08.21

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.