Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-1142PUBLISHED: 2023-03-27In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.
CVE-2023-1143PUBLISHED: 2023-03-27In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.
CVE-2023-1144PUBLISHED: 2023-03-27Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.
CVE-2023-1145PUBLISHED: 2023-03-27Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
CVE-2023-1655PUBLISHED: 2023-03-27Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.
User Rank: Ninja
9/3/2014 | 9:56:28 AM
Here is what I think it will take to convince executive management to elevate the whole security agenda. Imagine a company breach that results in a total electronic data loss in their production environment. Think about that for a second - no sales because they have no idea what products they have, no working POS system, no customer data, nothing in the form of electronic data processing ... nothing. Nothing moves in the company until their DR plans kick in and achieve business continuity. Data breaches do not stop business from continuing operations, but a total data loss will. When that happens to a big name brand like Target or Home Depot, then company executives will realize that a new phase has arrived in the threat horizon. Data loss is a very scary scenario, but business stoppage is like a stake through the heart, difficult to recover from within a short time frame. I really hope it does not come to that, and that executives everywhere wake up and smell the coffee before that happens to them.