Rewterz

Rewterz Threat Advisory – CVE-2020-2034 – Palo Alto OS command injection vulnerability in GlobalProtect portal

July 10, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-12025 – ICS: Rockwell Automation Logix Designer Studio 5000

July 10, 2020

Rewterz Threat Advisory – ICS: Phoenix Contact Automation Worx Software Suite

Severity

Medium

Analysis Summary

CVE-2020-12497

Due to insufficient input data validation while processing project files the buffer could be overflown. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.

CVE-2020-12498

Insufficient input data validation while processing project files could result in an out-of-bounds read. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.

Impact

  • Stack-based Buffer Overflow
  • Out-of-Bounds Read

Affected Vendors

Phoenix Contact

Affected Products

  • PC Worx version 1.87 and prior
  • PC Worx Express version 1.87 and prior

Remediation

Refer to ICS advisory for the complete list of affected products and respective patches.

https://us-cert.cisa.gov/ics/advisories/icsa-20-191-01

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.