Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-1142PUBLISHED: 2023-03-27In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.
CVE-2023-1143PUBLISHED: 2023-03-27In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.
CVE-2023-1144PUBLISHED: 2023-03-27Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.
CVE-2023-1145PUBLISHED: 2023-03-27Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.
CVE-2023-1655PUBLISHED: 2023-03-27Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.4.0.
User Rank: Ninja
12/27/2014 | 9:19:08 PM
Instead of getting angry to attackers or trying to get even we need to figure it what we do so we can avoid similar types of attacks.
@Dr. T Couldn't agree more. What we are actually witnessing is how leaders of industry ( film in this case ) mishandle the "new-age" world in which we live. I have heard everything from Sony except what they are doing so that this might never happen again.
I guess they really have no time to answer that question as they are busy working on their latest breech - their Playstation feeds.
Sony is really becoming a national "eye-sore". It might be time for those over paid leaders at Sony to actually earn their pay.
Don't count on it.