zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 14, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 14, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Vulnerabilities in CODESYS V3 Expose Millions of Industrial PLCs
  • Python Parsing Flaw Could Allow Attackers to Bypass Security Filters
  • Ford: Cars with WiFi Bug Safe to Drive
  • Data broker / initial-access broker / hacktivist group: Anonymous Collective and Alatus Aerosystems
  • Vulnerabilities: CVE-2020-13654 and CVE-2023-0950
  • Breaches: BreachForums: Noveo solutions and XSS/Nulled: Billy Hyde Music

Vulnerabilities in CODESYS V3 Expose Millions of Industrial PLCs

Millions of programmable logic controllers (PLCs) in global industrial settings are threatened by 15 vulnerabilities in the CODESYS V3 software development kit (SDK) that can allow remote code execution and denial of service attacks. Over 500 device manufacturers rely on the SDK for programming over 1,000 PLC models. After these bugs were reported in September 2022, the vendor released patches by April 2023. All impacted products should be upgraded to v3.5.19.0, and such critical devices should be disconnected from the internet.

Python Parsing Flaw Could Allow Attackers to Bypass Security Filters

A critical vulnerability (CVE-2023-24329) exists in the basic URL parsing (urllib.parse) function in Python. Versions preceding v3.11 are susceptible to exploitation, granting attackers the capability to bypass blocklisting techniques, which can lead to unauthorized file access, arbitrary command execution, and SSRF attacks. The security of urlsplit() and urlparse() APIs is compromised by inadequate input validation, potentially accepting non-standard inputs without error. Mitigations for this vulnerability have been implemented in Python version 3.7.17 and above.

Ford: Cars with WiFi Bug Safe to Drive

Ford has disclosed details of a bug in the SYNC 3 infotainment system on some Ford and Lincoln vehicles—while stating that the safety of vehicle occupants will not be compromised even in the unlikely event of the bug’s exploitation. There is no evidence to suggest the bug’s exploitation in the wild; moreover, exploiting it will require the attacker to be physically near a vehicle that has its ignition and WiFi setting on. Ford will soon issue a software patch online for download and installation via USB.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Anonymous Collective:: Threatening to attack the Japanese government in protest of “the dumping of radioactive contaminated water from the Fukushima nuclear accident in the Pacific Ocean.”
  • Alatus Aerosystems:: A Telegram channel is selling databases allegedly from the American aerospace machining, assembly, and welding company.

VULNERABILITIES

  • CVE-2020-13654 - XWiki Platform before 12.8 mishandles escaping in the property displayer..
  • CVE-2023-0950 - Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded.

BREACHES

  • BreachForums:: Noveo solutions Data Breach (409,611 Records)
  • XSS/Nulled:: Billy Hyde Music Data Breach (11,350 Records) | Company name, date of birth, email address, gender, name, phone number, and physical address

Tags: DIB, tlp:green