πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-20812 β€Ό

Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20768 β€Ό

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to access confidential information, some of which may contain personally identifiable information (PII). Note: To access the logs that are stored in the RoomOS Cloud, an attacker would need valid Administrator-level credentials.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-3172 β€Ό

EidoGo is susceptible to Cross-Site Scripting (XSS) attacks via maliciously crafted SGF input.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20791 β€Ό

A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. This vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the API to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system of the affected device. The attacker would need valid user credentials to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2014-8164 β€Ό

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20808 β€Ό

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of multiple simultaneous device registrations on Cisco SSM On-Prem. An attacker could exploit this vulnerability by sending multiple device registration requests to Cisco SSM On-Prem. A successful exploit could allow the attacker to cause a DoS condition on an affected device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27548 β€Ό

HCL Launch stores user credentials in plain clear text which can be read by a local user.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20815 β€Ό

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20813 β€Ό

Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device. For more information about these vulnerabilities, see the Details section of this advisory.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Prevention Takes Priority Over Response πŸ•΄

Cybersecurity teams continue to emphasize intrusion prevention over incident response, despite US government action.

πŸ“– Read

via "Dark Reading".
🀯1
β€Ό CVE-2022-2342 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32567 β€Ό

The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.

πŸ“– Read

via "National Vulnerability Database".
⚠ OpenSSL fixes two β€œone-liner” crypto bugs – what you need to know ⚠

"As bad as Heartbleed"? We heard that concern a week ago, but we think it's less ungood than that...

πŸ“– Read

via "Naked Security".
πŸ—“οΈ Fortinet patch batch remedies multiple path traversal vulnerabilities πŸ—“οΈ

Four high, six medium, and one low severity issue fixed

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Inside NIST's 4 Crypto Algorithms for a Post-Quantum World πŸ•΄

With the world potentially less than a decade away from breaking current encryption around critical data, researchers weigh in on planning for the post-quantum world.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-25046 β€Ό

A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25047 β€Ό

The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-1785 β€Ό

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31854 β€Ό

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-32206 β€Ό

curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression chain could result in a "malloc bomb", makingcurl end up spending enormous amounts of allocated heap memory, or trying toand returning out of memory errors.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2015-3207 β€Ό

In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.

πŸ“– Read

via "National Vulnerability Database".