Comunidad Pen7esting
3.61K subscribers
513 photos
40 videos
142 files
5.09K links
Download Telegram
Cisco StarOS Command Injection Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-staros-cmdinj-759mNT4n?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20StarOS%20Command%20Injection%20Vulnerability&vs_k=1

A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device.
This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user. To exploit this vulnerability, an attacker would need to have valid administrative credentials on an affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-staros-cmdinj-759mNT4n



Security Impact Rating: Medium



CVE: CVE-2022-20665
TODO SOBRE ETERNALBLUE.pdf
444.1 KB
Os vuelvo a enviar el PDF ya que he agregado un par de cosas.
Comunidad Pen7esting
Top10 de ataques al Directorio Activo https://www.hackplayers.com/2022/03/top10-de-ataques-al-directorio-activo.html
No olvidéis que he hecho creo que 4 scripts para este tema de Active Directory, si alguien no los ha visto y OS interesa, díganme y los comparto de nuevo.
Forwarded from REDSEG | Noticias
This media is not supported in your browser
VIEW IN TELEGRAM
LOS RIESGOS DE CARGAR UN VEHÍCULO ELÉCTRICO AL INTERIOR DE UN DOMICILIO

Suscríbase @redseg

🌐 REDSEG | Noticias
Noticias Destacadas del Sector Seguridad y Delincuencia de Alta Tecnología