CouRRier News Today
CouRRier News Today
Skip to content
  • Cybersecurity
  • Weather
  • Life
  • Sports
  • Loot
  • Local
  • FORUM

September 2024

There were 1,682 posts published in September 2024 (this is page 70 of 169).

Post navigation

Biden-Harris Administration Announces Final Awards through Landmark Meat and Poultry Processing Investment

WASHINGTON, Sept. 19, 2024 – U.S. Department of Agriculture (USDA) Secretary Tom Vilsack announced today that USDA is awarding more than $35 million in grants to 15 independent meat processors in 12 states to increase processing capacity, spur competition to expand market opportunities for U.S. farmers and create jobs in rural areas.

in Life | September 19, 2024 | 48 Words

Man, woman identified in crash that killed Franklin HS football player

in News | September 19, 2024 | 0 Words

Fantasy Basketball Rankings: Power forward draft tiers for 2024-25 NBA season

Fantasy basketball analyst Dan Titus continues his rankings tiers for the 2024-25 season with the power forwards!

in Sports | September 19, 2024 | 17 Words

Fantasy Basketball Rankings: Power forward draft tiers for 2024-25 NBA season

Fantasy basketball analyst Dan Titus continues his rankings tiers for the 2024-25 season with the power forwards!

in Sports | September 19, 2024 | 17 Words

This Southern California airport is the best in North America, survey says

in News | September 19, 2024 | 0 Words

This Southern California airport is the best in North America, survey says

in News | September 19, 2024 | 0 Words

A Fed rate cut with the stock market at a record high? Here’s what history says.

in Money, News | September 19, 2024 | 0 Words

IDEC CORPORATION WindLDR and WindO/I-NV4

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 5.9
  • ATTENTION: Exploitable remotely
  • Vendor: IDEC Corporation
  • Equipment: WindLDR, WindO/I-NV4
  • Vulnerability: Cleartext Storage of Sensitive Information

2. RISK EVALUATION

Successful exploitation of this vulnerability could allow an attacker to obtain sensitive information.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following versions of WindLDR and WindO/I-NV4 are affected:

  • WindLDR: Ver.9.1.0 and prior
  • WindO/I-NV4: Ver.3.0.1 and prior

3.2 Vulnerability Overview

3.2.1 CLEARTEXT STORAGE OF SENSITIVE INFORMATION CWE-312

The affected products are vulnerable to a cleartext vulnerability that could allow an attacker to obtain user authentication information.

CVE-2024-41716 has been assigned to this vulnerability. A CVSS v3.1 base score of 5.9 has been calculated; the CVSS vector string is (/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

3.3 BACKGROUND

  • CRITICAL INFRASTRUCTURE SECTORS: Food and Agriculture, Critical Manufacturing, Energy, Transportation
  • COUNTRIES/AREAS DEPLOYED: Worldwide
  • COMPANY HEADQUARTERS LOCATION: Japan

3.4 RESEARCHER

Yuki Meguro of Toinx Co., Ltd. reported this vulnerability to IPA.

4. MITIGATIONS

Apply the appropriate software update according to the information provided by the developer:

  • WindLDR: Ver.9.2.0
  • WindO/I-NV4: Ver.3.1.0

For more information, reference the IDEC Corporation advisory:

  • WindLDR and WindO/I-NV4 store sensitive information in cleartext

CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:

  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.

5. UPDATE HISTORY

  • September 19, 2024: Initial Publication
in Cybersecurity, DHS | September 19, 2024 | 438 Words

Elon Musk Says Warren Buffett Is Positioning For Kamala Harris Win With His $277B Cash Pile As Pro-Trumper John Paulson Warns Of Equity Market Exit

in Money, News | September 19, 2024 | 0 Words

Yankees clinch playoff spot after Julio Rodríguez’s baserunning disaster

For the second straight game, the Mariners made a catastrophic baserunning mistake.

in Sports | September 19, 2024 | 12 Words

Post navigation

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • July 2020
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • June 2013
  • April 2012
  • March 2012
  • February 2012
  • October 1839

Meta

  • Log in
Independent Publisher empowered by WordPress