πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2019-14480 β€Ό

AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25621 β€Ό

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5360 β€Ό

Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25620 β€Ό

An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14248 β€Ό

BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-25622 β€Ό

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-5359 β€Ό

Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-26198 β€Ό

Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victimÒ€ℒs browser by tricking a victim in to following a specially crafted link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-14254 β€Ό

TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-4008 β€Ό

The installer of the macOS Sensor for VMware Carbon Black Cloud prior to 3.5.1 handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Zeek 3.2.3 πŸ› 

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. While focusing on network security monitoring, Zeek provides a comprehensive platform for more general network traffic analysis as well. Well grounded in more than 15 years of research, Zeek has successfully bridged the traditional gap between academia and operations since its inception. Today, it is relied upon operationally in particular by many scientific environments for securing their cyber-infrastructure. Zeek's user community includes major universities, research labs, supercomputing centers, and open-science communities. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
❌ Ryuk, Egregor Ransomware Attacks Leverage SystemBC Backdoor ❌

In the past few months researchers have detected hundreds of attempted SystemBC deployments globally, as part of recent Ryuk and Egregor ransomware attacks.

πŸ“– Read

via "Threat Post".
πŸ•΄ Why the Weakest Links Matter πŸ•΄

The recent FireEye and SolarWinds compromises reinforce the fact that risks should be understood, controls should be in place, and care should be taken at every opportunity.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Senior Managers Twice as Likely to Share Work Devices With Outsiders πŸ•΄

New survey finds top C-suite managers are much shakier on security than their junior counterparts.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2020-7781 β€Ό

This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14479 β€Ό

AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14481 β€Ό

AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-7837 β€Ό

An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer overflow via access to crafted web page. This issue affects: Infraware ML Report 2.19.312.0000.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14476 β€Ό

AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2019-14478 β€Ό

AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript code in the context of the user's browser if the victim opens or searches for a node whose "Display Name" contains an XSS payload.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-35133 β€Ό

irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.

πŸ“– Read

via "National Vulnerability Database".