
SEC Consult
@sec_consult
YOUR GLOBAL PARTNER FOR CYBERSECURITY. SEC Consult is part of Eviden. @Evidenlive
ID: 888212952
https://www.sec-consult.com 18-10-2012 06:18:26
1,1K Tweet
2,2K Followers
316 Following

Issues like this emphasize the need for stringent cybersecurity measures across critical sectors r.sec-consult.com/hasomed Thanks for the fast und professional response Elefant Praxissoftware #EU #CyberResilienceAct #infosec #criticalInfrastructure #CVD


Some things are best kept "unclear". Like passwords to control levels. r.sec-consult.com/t3000 Multiple vulnerabilities in Siemens Energy Omnivise T3000 control systems allowed attackers to e.g. elevate the privileges to an administrative user and take it from there #infosec



Learn more about "SMTP Smuggling Revisited โ Still Spoofing E-mails Worldwide?!" - Timo Lo(n)gin | Nov 23, 14:10 | BSidesVienna.at #teamsecconsult bsidesvienna.at


๐จ Critical Vulnerabilities Found in High-End Network Scanners! 14 critical vulnerabilities in Image Access Scan2Net platform (firmware โค7.42), including RCE via OS Command Injection, Privilege Escalation, XSS, SQL Injection, & more r.sec-consult.com/imageaccess


Critical industries rely on Wind River VxWorks, but a weakness in its #password hashing raises serious security concerns.๐Expert Stefan Viehbรถck breaks down the issue, the vendorโs response, and how it shouldโve been addressed ๐ r.sec-consult.com/vxblog ๐ Technical advisory & PoC also









๐ Chained RCE found โ and fixed right! Our Vulnerability Lab discovered critical issues in the MEDICAL OFFICE demo by INDAMED. Textbook CVD: Fixes scheduled, production not affected. ๐ Kudos to INDAMED for their professional response. ๐ r.sec-consult.com/indamed #CyberSecurity

๐ Undocumented Root Shell on SIMCom Wireless Modem: โ ๏ธ Unauth. control โ ๏ธ Firmware manipulation, backdoors โ No patch available yet CPOs: Secure device,monitor logs, Reach out to SIMCom Wireless ๐ Full advisory: r.sec-consult.com/simcom


Reflected XSS in #ONLYOFFICE Docs โคv8.3.1 via crafted WOPI requests โ allows JS injection, session hijacking & phishing ๐ก๏ธFixed in v8.3.2 โ update now! ๐ Patch & : github.com/ONLYOFFICE/Docโฆ ๐ Advisory: r.sec-consult.com/onlyoffice #InfoSec #CyberSecurity #XSS The ONLYOFFICE

