πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Many ZTNA, MFA Tools Offer Little Protection Against Cookie Session Hijacking Attacks πŸ•΄

Many of the technologies and services that organizations are using to isolate Internet traffic from the internal network lack session validation mechanisms, security startup says.

πŸ“– Read

via "Dark Reading".
πŸ—“οΈ Black Hat USA: Former CISA director Chris Krebs warns clouds of cyberwar are circling Taiwan πŸ—“οΈ

Attack on Taiwan seemingly a case of β€˜when’ not β€˜if’ Chris Krebs, the former director of the US Cybersecurity and Infrastructure Security Agency (CISA), is β€œbearish in the short term, bullish in the l

πŸ“– Read

via "The Daily Swig".
πŸ•΄ Multiple Vulnerabilities Discovered in Device42 Asset Management Appliance πŸ•΄

Four serious security issues on the popular appliance could be exploited by hackers with any level of access within the host network, Bitdefender researchers say.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-20360 β€Ό

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-30580 β€Ό

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35538 β€Ό

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_delete_list and b_delete_al_mac, which leads to command injection in page /wifi_mesh.shtml.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20356 β€Ό

In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service from background due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215003903

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20345 β€Ό

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-230494481

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-1962 β€Ό

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-20355 β€Ό

In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-219498290

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37001 β€Ό

The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37006 β€Ό

Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37007 β€Ό

The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35536 β€Ό

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to command injection in page /qos.shtml.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37003 β€Ό

The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36923 β€Ό

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38129 β€Ό

A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35526 β€Ό

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.shtml.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35535 β€Ό

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection in page /wifi_mesh.shtml.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36750 β€Ό

Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-37002 β€Ό

The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.

πŸ“– Read

via "National Vulnerability Database".