휴네시온 아이원넷(i-oneNet) 망연계 솔루션 보안 업데이트 권고
2019-05-10 • KRCERT • Hunession i-oneNet network connection solution security update recommendation •
KrCERT/CC warned that Hunesion's i-oneNet network-separation file-transfer solution contained two security vulnerabilities affecting versions 3.0.7 through 3.0.53 and 4.0.4 through 4.0.16. CVE-2019-12803 allowed unauthorized arbitrary file uploads to the network-linkage system, while CVE-2019-12804 involved insufficient integrity verification for user program update files. The advisory recommends applying the vendor security patches 3.0.xx_S001 or 4.0.xx_S001, or upgrading to fixed versions 3.0.54 or 4.0.17 and later. The excerpt does not attribute exploitation to any actor, but the flaws matter because file upload and update-integrity weaknesses in cross-network transfer products can create high-impact intrusion paths if left unpatched.