CISA

CISA Malcolm

From Cybersecurity and Infrastructure Security Agency ↗

The following versions of CISA Malcolm are affected:

Malcolm

Vendor

Equipment

CISA

CISA Malcolm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site ('Open Redirect'), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort

Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater

Countries/Areas Deployed: Worldwide

Company Headquarters Loca...