Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-23087PUBLISHED: 2023-02-03An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function.
CVE-2023-23088PUBLISHED: 2023-02-03Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.
CVE-2023-0659PUBLISHED: 2023-02-03
A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The identifier VD...
CVE-2023-23086PUBLISHED: 2023-02-03Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.
CVE-2021-37519PUBLISHED: 2023-02-03Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
User Rank: Apprentice
9/23/2015 | 9:35:16 AM
That said....
Q1 - I'm curious though if there are any initiatives in the works to work with these IoT companies when it comes to interacting with security researchers (outside said company/ies), their response and reaction to bugs, exploits, zero days etc that are brought to their attention especially in good faith.
And
Q2 - Once informed, how to categorize and address the disclosed issue within the company. Is it a "stop everything and get this fixed asap" issue because said company may have early beta equipment in-use in the wild (customers) and may feel the issue is enough of a threat to apply most of their resources to fixing said issue (at least those resources necessary to address the issue) even if it means taking those resources away from their current work (perhaps in the midst of meeting a deadline?) I realize it's all contextual and we could all come up with 100 different scenarios but it should be noted that a lot of start-ups are going to be riding a fine line with deadlines, money, perception etc and likely won't be able to weather a misstep quite as well as the larger more established companies.