CVE-2021-38399 - How Path Traversal in Honeywell Experion PKS Controllers Almost Opened the Floodgates
---
Overview
_CVE-2021-38399_ is a serious security weakness in Honeywell’s widely-deployed Experion Process Knowledge System (PKS), particularly in the C200, C200E, C300,
CVE-2022-43000 The DIR-816 A2 1.10 B05 was found to have a stack overflow vulnerability.
This was fixed by updating the firmware to version 1.09 B04. This issue did not affect the majority of users. It is important to
CVE-2022-43775 - Exploiting SQL Injection in Delta Electronics DIAEnergy (v1.9) — How Attackers Could Take Over Remote Systems
In late 2022, cybersecurity researchers discovered a critical vulnerability, tracked as CVE-2022-43775, in the DIAEnergy v1.9 system developed by Delta Electronics. The
CVE-2022-43774 - Dangerous SQL Injection Exploit in Delta Electronics DIAEnergy v1.9’s HandlerPageP_KID Class
If you work with industrial automation or energy management systems, you might know Delta Electronics’ popular DIAEnergy software. In its v1.9 release, a serious
CVE-2022-40238 An RCE vulnerability exists in CERT software prior to version 1.50.5. An attacker can inject arbitrary pickle object as part of a user's profile.
This vulnerability can be exploited via Authentication bypass. A Remote Code Execution vulnerability in CERT software prior to version 1.50.5 can be exploited
Episode
00:00:00
00:00:00