Skip to content
  Saturday 11 April 2026
Trending
April 3, 2025Senior Manager of Cybersecurity Detection Engineering January 22, 2026CISA Adds Four Known Exploited Vulnerabilities to Catalog December 5, 2025Clinical Assistant Professor of Cybersecurity October 28, 2024Cybersecurity Officer for Sustainability Business March 19, 2024Audit Director – IT/Cybersecurity October 22, 2024DPI Global Cybersecurity Governance Apprentice December 29, 2024The rising popularity of plant-based diets is transforming the way people eat and think about food. This shift is driven by a growing awareness of the health benefits of a plant-based diet, as well as concerns about the environmental impact of animal agriculture. Many people are choosing to incorporate more fruits, vegetables, grains, and legumes into their meals, while reducing or eliminating their consumption of animal products.<br /> <br /> Plant-based diets have been shown to lower the risk of chronic diseases such as heart disease, diabetes, and cancer. They are also rich in essential nutrients like fiber, vitamins, and antioxidants that are important for overall health. By focusing on plant foods, people can improve their well-being and prevent the onset of various health issues.<br /> <br /> In addition to the health benefits, plant-based diets are also better for the environment. Animal agriculture is a major contributor to greenhouse gas emissions, deforestation, and water pollution. By reducing the demand for animal products, individuals can help to reduce their carbon footprint and lessen the strain on the planet’s resources.<br /> <br /> The popularity of plant-based diets has led to a proliferation of plant-based food products in grocery stores and restaurants. From plant-based burgers and dairy alternatives to vegan desserts and snacks, there are more options than ever for those looking to eat more plant-based foods. This trend is making it easier for people to adopt a plant-based diet and enjoy delicious, nutritious meals without sacrificing taste or convenience.<br /> <br /> Overall, the rise of plant-based diets represents a positive shift towards a more sustainable and health-conscious way of eating. By choosing to incorporate more plant foods into our diets, we can improve our health, reduce our environmental impact, and support a more ethical and compassionate food system. Whether for health, environmental, or ethical reasons, plant-based diets are a win-win for individuals and the planet alike. May 8, 2025SENIOR CYBERSECURITY BUSINESS ANALYST October 13, 2023Overview of Features, Pricing, Advantages, and Disadvantages January 1, 2025Cybersecurity Supervisor (Administrative Supervisor 4)
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
  Threat Advisories  ​Weintek Weincloud | CISA
Threat Advisories

​Weintek Weincloud | CISA

Mister CybersecurityMister Cybersecurity—July 19, 20230
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail


1. EXECUTIVE SUMMARY

  • ​CVSS v3 9.8
  • ​ATTENTION: Exploitable remotely/low attack complexity
  • ​Vendor: Weintek
  • ​Equipment: Weincloud
  • ​Vulnerabilities: Weak Password Recovery Mechanism for Forgotten Password, Improper Authentication, Improper Restriction of Excessive Authentication Attempts, Improper Handling of Structural Elements

2. RISK EVALUATION

​Successful exploitation of these vulnerabilities could allow an attacker to utilize the JSON web token (JWT) to reset account passwords, use expired credentials, perform brute force attacks on credentials, or cause a denial-of-service condition.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

​The following Weintek Weincloud versions are affected: 

3.2 VULNERABILITY OVERVIEW

3.2.1 ​WEAK PASSWORD RECOVERY MECHANISM FOR FORGOTTEN PASSWORD CWE-640

​The affected product could allow an attacker to reset a password with the corresponding account’s JWT token only.

​CVE-2023-35134 has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

3.2.2 ​IMPROPER AUTHENTICATION CWE-287

​The affected product could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.

​CVE-2023-37362 has been assigned to this vulnerability. A CVSS v3 base score of 7.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

3.2.3 ​IMPROPER RESTRICTION OF EXCESSIVE AUTHENTICATION ATTEMPTS CWE-307

More stories

New CISA Plan Aligns Federal Agencies in Cyber Defense

September 16, 2024

Inosoft VisiWin | CISA

May 30, 2024

Labkotec LID-3300IP | CISA

March 4, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

July 10, 2025

​The affected product could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.

​CVE-2023-32657 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

3.2.4 ​IMPROPER HANDLING OF STRUCTURAL ELEMENTS CWE-237

​The affected product could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.

​CVE-2023-34429 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

3.3 BACKGROUND

  • ​CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing
  • ​COUNTRIES/AREAS DEPLOYED: Worldwide
  • ​COMPANY HEADQUARTERS LOCATION: Taiwan

3.4 RESEARCHER

​Hank Chen (PSIRT and Threat Research of TXOne Networks) reported these vulnerabilities to CISA.

4. MITIGATIONS

​Weintek has updated their account API to v0.13.8, which has fixed the issue. This fix does not require any action for users.

​Additional mitigations are recommended to help reduce risk:

  • ​Log in on trusted computers if possible. Log out after usage on un-trusted ones.
  • ​On the HMIs, if the online services are not used, set to offline mode for EasyAccess 2.0 or Dashboard services using system reserved addresses.
  • ​Regularly change passwords to reduce risks. 
  • ​Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible- only applicable devices and/or systems have access to the internet.

​CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Specifically, users should:

  • ​Locate control system networks and remote devices behind firewalls and isolate them from business networks.
  • ​When remote access is required, use secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as its connected devices.

​CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

​CISA also provides a section for control systems security recommended practices on the ICS webpage at cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

​Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

​Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

​No known public exploits specifically target these vulnerabilities.



Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

Mister Cybersecurity

CISA Releases Seven Industrial Control Systems Advisories
Rockwell Automation Kinetix 5700 DC Bus Power Supply
Related posts
  • Related posts
  • More from author
Threat Advisories

Contemporary Controls BASC 20T | CISA

April 9, 20260
Threat Advisories

GPL Odorizers GPL750 | CISA

April 9, 20260
Threat Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

April 8, 20260
Load more
Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Careers

Cybersecurity Resilience Specialist – Governance Risk and Compliance

April 11, 20260
Careers

Principal Cybersecurity – Cloud Security Strategy

April 11, 20260
Careers

Cybersecurity Engineer

April 11, 20260
Careers

Cybersecurity Engineer Principal

April 11, 20260
Careers

Cybersecurity Analyst III, Patch Management

April 11, 20260
Careers

Cybersecurity Engineering Support

April 11, 20260
Load more
Stay Social!
192Likes
4,500Followers
13Subscribers
46Followers
Recent posts
  • Cybersecurity Resilience Specialist – Governance Risk and Compliance
  • Principal Cybersecurity – Cloud Security Strategy
  • Cybersecurity Engineer
  • Cybersecurity Engineer Principal
  • Cybersecurity Analyst III, Patch Management

    # TRENDING

    how old is my computerhow old is my dell laptophow old is my HP laptophow old is my laptophow old is my toshiba laptophow to find computer ageverify computer agestar wars theme wallpapersThe Best Hacking Bookswiresharkusb device not found windows 10/11usb device not recognized windows 10/11 errorWhat is AIGPUSnifferuTorrentvulnerability scanner downloadWifi Hacking SoftwareWifi Hacking Appsolved windows 10/11 usb device not recognizedstar wars windows 7 theme downloadTwitter Account Security
    © Copyright Mister Cybersecurity LLC 2023, All Rights Reserved
    • About
    • Contact
    • Privacy
    • ToS
    • Disclosures