NSIDE

About NSIDE

This author has not yet filled in any details.
So far NSIDE has created 18 blog entries.

The Cyber Resilience Act (CRA) in relation to Pentests

Does the Cyber Resilience Act Make Penetration Testing Mandatory?

No — and yet hardly any manufacturer will get by without structured security testing. Why both are true at the same time, and what question really matters.

“Does the Cyber Resilience Act now require penetration testing?” — we’ve been getting this question for months. The honest answer is: No. And yet, for most manufacturers, there is no way around structured security testing. Both are true at the same time — and it’s precisely in this apparent contradiction that the point lies, one that many companies are still underestimating in 2026.

The Cyber Resilience Act (Regulation (EU) 2024/2847) is deliberately method-neutral. It does not name any specific testing technique — neither “penetration test” nor “fuzzing” nor “DAST” appear as […]

By |2026-08-10T15:53:14+02:007. August 2026|

Cybersecurity in Sweden

Cybersecurity in Sweden 2025 – Hybrid Threats, NIS2 & Resilience Strategies

Introduction: Sweden’s digital strength meets new exposure

Sweden’s digital economy is among Europe’s most advanced – and most connected.

Public services, healthcare, and even maritime navigation depend on a seamless data flow.

But 2025 has also marked a turning point: since joining NATO, Sweden has become a visible node in the geopolitical network – and that visibility attracts unwanted attention.

Foreign-sponsored operations, ransomware campaigns against municipalities, and targeted disinformation now appear in parallel.

The question for Swedish organisations is no longer if they’ll be tested – but how prepared they are when it happens.

1. The geopolitical backdrop: a new reality for Swedish cybersecurity

Sweden’s alignment with NATO redefined its threat surface.

While state-sponsored cyber campaigns […]

By |2025-12-19T15:17:15+01:003. November 2025|

[CVE-2014-5335] CSRF in Innovaphone PBX

Innovaphone PBX Admin-GUI CSRF

Impact: High
CVSS2 Score: 7.8 (AV:N/AC:M/Au:S/C:P/I:C/A:C/E:F/RL:U/RC:C)
Announced: August 21, 2014
Reporter: Rainer Giedat (NSIDE ATTACK LOGIC GmbH, https://www.nsideattacklogic.de/)
Products: Innovaphone PBX Administration GUI
Affected Versions: all known versions (tested 10.00 sr11)
CVE-id: CVE-2014-5335

Summary

The innovaphone PBX is a powerful and sophisticated VoIP telephone system for use in professional business environments. In addition to a wide range of IP telephony functionalities, the innovaphone PBX is also equipped with a perfectly integrated Unified Communications solution that can be enabled as needed at any time and at any workspace.

The innovaphone PBX uses a web-based user interface. This UI is vulnerable to cross-site request forgery attacks (CSRF).

Description

The UI does not check if a request was sent originating from a page it delivered before or from an untrusted and potentially malicious source. With a […]

By |2022-05-19T17:10:09+02:0021. August 2014|
Go to Top