Malware Devil

Wednesday, February 17, 2021

White House Says 100 Private Sector Orgs Hit in SolarWinds Campaign

Register for Dark Reading Newsletters

Subscribe to Newsletters

White Papers

Video

Cartoon Contest

Current Issue

image2021 Top Enterprise IT TrendsWe’ve identified the key trends that are poised to impact the IT landscape in 2021. Find out why they’re important and how they will affect you today!
image

Flash Poll

Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
image

Twitter Feed

Dark Reading - Bug Report

Bug Report

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database
CVE-2020-13550
PUBLISHED: 2021-02-17

A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

CVE-2020-13551
PUBLISHED: 2021-02-17

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

CVE-2020-13552
PUBLISHED: 2021-02-17

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execu…

CVE-2020-13553
PUBLISHED: 2021-02-17

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT …

CVE-2020-13555
PUBLISHED: 2021-02-17

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

The post White House Says 100 Private Sector Orgs Hit in SolarWinds Campaign appeared first on Malware Devil.



https://malwaredevil.com/2021/02/17/white-house-says-100-private-sector-orgs-hit-in-solarwinds-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=white-house-says-100-private-sector-orgs-hit-in-solarwinds-campaign

No comments:

Post a Comment

Barbary Pirates and Russian Cybercrime

In 1801, the United States had a small Navy. Thomas Jefferson deployed almost half that Navy—three frigates and a schooner—to the Barbary C...