Security Affairs
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112|Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch|Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION|Hack One Robot, Reach the Next: Unitree G1 Security Flaws|Rhysida Ransomware Group Targets Berlin Government Ahead of Vote|Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator|Love Electric Breach: 877,000 Driver Records Offered for $600|Trump Targets Foreign Technology in New U.S. Power Grid Security Order|U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112|Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch|Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION|Hack One Robot, Reach the Next: Unitree G1 Security Flaws|Rhysida Ransomware Group Targets Berlin Government Ahead of Vote|Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator|Love Electric Breach: 877,000 Driver Records Offered for $600|Trump Targets Foreign Technology in New U.S. Power Grid Security Order|U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Resecurity identified a zero-day vulnerability in Schneider Electric Accutech Manager

Resecurity researchers identified a zero-day Buffer Overflow vulnerability in the Schneider Electric Accutech Manager product. Resecurity identified a zero-day vulnerability in the Schneider Electric Accutech Manager product. The vulnerability, labeled as CVE-2023-29414 and SEVD-2-23-192-03, has been rated high with a CVSS v3.1 Base Score of 7.8. This issue pertains to a Buffer Overflow exploitation (CWE-120) […]

Schneider Electric Accutech Manager

Resecurity researchers identified a zero-day Buffer Overflow vulnerability in the Schneider Electric Accutech Manager product.

Resecurity identified a zero-day vulnerability in the Schneider Electric Accutech Manager product. The vulnerability, labeled as CVE-2023-29414 and SEVD-2-23-192-03, has been rated high with a CVSS v3.1 Base Score of 7.8.

This issue pertains to a Buffer Overflow exploitation (CWE-120) found in version 2.7 and earlier versions of the product. If exploited, it could lead to user privilege escalation, especially if a local user sends a specific string input to a local function call.

Resecurity’s HUNTER team was quick to detect this vulnerability and promptly issued an early-warning alert to Schneider Electric Product Security Team. They further assisted Schneider Electric by providing a working Proof-of-Concept (POC), ensuring a swift resolution to the problem.

Schneider Electric Accutech Manager

Schneider Electric Accutech Manager

The energy and industrial sectors are vital backbones of our modern society. Recognizing the importance of safeguarding these sectors, Resecurity remains steadfast in its commitment to ensuring the protection of critical infrastructure on a global scale. The firm believes in paving the way for a secure digital future, where the integrity of essential industrial control systems (ICS) and their components (SCADA, RTU) remains protected from cyberattacks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, buffer overflow)