Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-12512PUBLISHED: 2021-01-22Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
CVE-2020-12513PUBLISHED: 2021-01-22Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
CVE-2020-12514PUBLISHED: 2021-01-22Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd
CVE-2020-12525PUBLISHED: 2021-01-22M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
CVE-2020-12511PUBLISHED: 2021-01-22Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
User Rank: Author
1/8/2015 | 3:23:31 PM
I probably did sound contradictary in the comments you highlighted. Great catch. I did not do a good job in defining where I am talking about threat and where i am talking about data/applications.
In the first reference, I was referring to Data and Applications. In other words, you cannot protect all of your data and applications, you should aggressively segement and control access to your company crown jewels.
In the second reference, I am referring to threat. I am trying to coach CISO's and business owners to assume you are a target. Too many companies, like CodeSpaces, probably believe they are not a target because they do not have something of value to criminals (i.e. Credit card data, Electronic Health Records). Even in this case, these companies should still NOT try to protect their whole environment, especially if it is very complex or dynamic. They should still identify the company crown jewels and aggressively segement. In the use case of CodeSpaces, they might have been saved by 2 factor auth for their admin access to their cloud envrionment.
Hopefully that clears up the confusion, thanks for asking for clarification.