πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-23972 β€Ό

ASUS RT-AX56UÒ€ℒs SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22515 β€Ό

A remote, unauthenticated attacker could utilize the control programmer of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22519 β€Ό

A remote, authenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver and the CODESYS Control runtime system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26671 β€Ό

Taiwan Secom Dr.ID Access Control systemÒ€ℒs login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0677 β€Ό

Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276. Bitdefender GravityZone versions prior to 26.4-1. Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.1.111.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22514 β€Ό

An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. This causes a null pointer dereference in the CmpSettings component of the affected CODESYS products and leads to a crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25595 β€Ό

ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of service by sending particular request a server-to-client reply attempt.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43432 β€Ό

A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25594 β€Ό

MicroprogramÒ€ℒs parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote attacker can input specific URLs to acquire partial system configuration information.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘2
β€Ό CVE-2022-22517 β€Ό

An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25597 β€Ό

ASUS RT-AC86UÒ€ℒs LPD service has insufficient filtering for special characters in the user request, which allows an unauthenticated LAN attacker to perform command injection attack, execute arbitrary commands and disrupt or terminate service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0935 β€Ό

Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23971 β€Ό

ASUS RT-AX56UÒ€ℒs update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another PLC/PORT file with the same file name, which results in service disruption.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22518 β€Ό

A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part of the applied security policy.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23973 β€Ό

ASUS RT-AX56UÒ€ℒs user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient validation for parameter length. An unauthenticated LAN attacker can execute arbitrary code to perform arbitrary operations or disrupt service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26676 β€Ό

aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25596 β€Ό

ASUS RT-AC56UÒ€ℒs configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for the decryption parameter length, which allows an unauthenticated LAN attacker to execute arbitrary code, perform arbitrary operations and disrupt service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-43430 β€Ό

An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26675 β€Ό

aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-23970 β€Ό

ASUS RT-AX56UÒ€ℒs update_json function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated LAN attacker can overwrite a system file by uploading another file with the same file name, which results in service disruption.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Scan This: There's Danger in QR Codes πŸ•΄

Trendy restaurant tables now feature QR codes that lead to menus, payment apps, and CISO nightmares.

πŸ“– Read

via "Dark Reading".