Thursday, November 17, 2022

Review - 2 Advisories Published – 11-17-22

Today CISA’s NCCIC-ICS published two control system security advisories for products from Cradlepoint and Red Lion.

Cradlepoint Advisory - This advisory describes a command injection vulnerability in the Cradlepoint NetCloud OS.

Red Lion Advisory - This advisory describes a path traversal vulnerability in the Red Lion Controls Crimson programming software.

 

For more details about these advisories, including a down-the-rabbit hole look at the Cradlepoint advisory, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/2-advisories-published-11-17-22 - subscription required.

No comments:

 
/* Use this with templates/template-twocol.html */