CouRRier News Today
CouRRier News Today
Skip to content
  • Cybersecurity
  • Weather
  • Life
  • Sports
  • Loot
  • Local
  • FORUM

June 2024

There were 1,723 posts published in June 2024 (this is page 62 of 173).

Post navigation

NBA free agency: Top shooting guards on the market

There are plenty of intriguing shooting guards available this offseason for teams looking to make a splash.

in Sports | June 20, 2024 | 17 Words

Fantasy Baseball Weekend Preview: 3 key hitting matchups to take advantage of

Ready for the weekend, fantasy baseball managers? Check out our blueprint for getting a leg up on the competition.

in Sports | June 20, 2024 | 19 Words

A closer look at Michael Jordan’s 1988 DPOY award raises questions about its validity. Has LeBron James been chasing a ghost?

New research reveals Jordan’s Defensive Player of the Year season likely included home-biased stats.

in Sports | June 20, 2024 | 14 Words

USDA Releases Updated Climate Adaptation and Resilience Plan

WASHINGTON, June 20, 2024 – Today, the U.S. Department of Agriculture (USDA) joined more than 20 federal agencies to release its updated Climate Adaptation Plan and expand the Biden-Harris Administration’s efforts to ensure federal operations are increasingly resilient to climate change impacts.

in Life | June 20, 2024 | 40 Words

Live from the 2024 MLB Draft Combine + JJ Wetherholt interview & Triple-A challenge system changing

Jake Mintz and Jordan Shusterman discuss being at the 2024 MLB Draft Combine, talk with potential first round draft pick JJ Wetherholt about his upbringing in baseball and get into why MLB is changing their review system in Triple-A.

in Sports | June 20, 2024 | 38 Words

The Wemby Wave: A flood of talent from France is following Victor Wembanyama to the NBA

The 2024 NBA Draft, and the years to come, will feature a new generation of top prospects from France.

in Sports | June 20, 2024 | 18 Words

The Wemby Wave: How a French connection reshaped the NBA Draft

The 2024 NBA Draft — and the years to come — will feature a new generation of top prospects from France. Merci beaucoup, Victor Wembanyama.

in Sports | June 20, 2024 | 22 Words

McDonald’s releases a new $5 value meal to combat inflation

in News | June 20, 2024 | 0 Words

CAREL Boss-Mini

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v4 9.3
  • ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
  • Vendor: CAREL
  • Equipment: Boss-Mini
  • Vulnerability: Path Traversal

2. RISK EVALUATION

Successful exploitation of this vulnerability could allow an attacker to manipulate an argument path, which would lead to information disclosure.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following versions of CAREL Boss-Mini, a local supervisor solution, are affected:

  • Boss-Mini: Version 1.4.0 (Build 6221)

3.2 Vulnerability Overview

3.2.1 IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY (‘PATH TRAVERSAL’) CWE-22

Under certain conditions, a malicious actor already present in the same network segment of the affected product, could abuse Local File Inclusion (LFI) techniques to access unauthorized file system resources, such as configuration files, password files, system logs, or other sensitive data. This could expose confidential information and potentially lead to further threats.

CVE-2023-3643 has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

A CVSS v4 score has also been calculated for CVE-2023-3643. A base score of 9.3 has been calculated; the CVSS vector string is (CVSS4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).

3.3 BACKGROUND

  • CRITICAL INFRASTRUCTURE SECTORS: Commercial Facilities
  • COUNTRIES/AREAS DEPLOYED: Worldwide
  • COMPANY HEADQUARTERS LOCATION: Italy

3.4 RESEARCHER

Werley Ferreira, Anderson Cezar, João Luz reported this vulnerability to CAREL.

4. MITIGATIONS

CAREL recommends updating to v1.6.0 or later

If immediate upgrade is not possible, users should consider and implement the following mitigations:

  • Ensure that default login credentials have been changed;
  • Use strong, non-compromised passwords (i.e. passwords making use of uppercase and lowercase letters, special characters and numbers)
  • Ensure the device has been deployed in a segregated internal network as per CAREL’s security recommendations (doc code +030220471 available at carel.com).

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

5. UPDATE HISTORY

  • June 20, 2024: Initial Publication
in Cybersecurity, DHS | June 20, 2024 | 551 Words

CISA Releases Guidance on Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses: (SMBs)

Today, CISA released Barriers to Single Sign-On (SSO) Adoption for Small and Medium-Sized Businesses: Identifying Challenges and Opportunities, a detailed report exploring challenges to SSO adoption by small and medium-sized businesses (SMBs). The report also identifies potential ways to overcome these challenges and improve an SMB’s level of security. 

CISA also released a related blog post, Why SMBs Don’t Deploy Single Sign-On (SSO), urging software manufacturers to consider how their business practices may inadvertently reduce the security posture of their customers.

For more information, visit CISA’s Secure by Design webpage. To learn more about identity and access management, visit Identity, Credential, and Access Management (ICAM).

in Cybersecurity, DHS | June 20, 2024 | 108 Words

Post navigation

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • July 2020
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • June 2013
  • April 2012
  • March 2012
  • February 2012
  • October 1839

Meta

  • Log in
Independent Publisher empowered by WordPress