๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-20853 โ€ผ

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24836 โ€ผ

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28697 โ€ผ

Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-47758 โ€ผ

Nanoleaf firmware v7.1.1 and below is missing an SSL certificate, allowing attackers to execute arbitrary code via a DHCP hijacking attack.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26244 โ€ผ

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the digital signature check of AppUpgrade and .lge.upgrade.xml files, which are used during the firmware installation process. This indirectly allows an attacker to use a custom version of AppUpgrade and .lge.upgrade.xml files.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26243 โ€ผ

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and initialization vector from memory. An attacker may exploit this to create custom firmware that may be installed in the IVI system. Then, an attacker may be able to install a backdoor in the IVI system that may allow him to control it, if it is connected to the Internet through Wi-Fi.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-20852 โ€ผ

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-26245 โ€ผ

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is used during the firmware installation process, can be modified by an attacker to bypass the version check in order to install any firmware version (e.g., newer, older, or customized). This indirectly allows an attacker to install custom firmware in the IVI system.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2297 โ€ผ

The Profile Builder รขโ‚ฌโ€œ User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (wppb_front_end_password_recovery). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-0814, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-22901 โ€ผ

ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administratorรขโ‚ฌโ„ขs privilege can exploit this vulnerability to access arbitrary system files.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2323 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-28770 โ€ผ

The sensitive information exposure vulnerability in the CGI รขโ‚ฌล“Export_Logรขโ‚ฌ๏ฟฝ and the binary รขโ‚ฌล“zcmdรขโ‚ฌ๏ฟฝ in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ“ข Microsoft links PaperCut server attacks to Cl0p, LockBit ransomware ๐Ÿ“ข

Microsoft Threat Intelligence noted attacks were facilitated by GoAnywhere vulnerabilities and the Raspberry Robin worm

๐Ÿ“– Read

via "ITPro".
โ€ผ CVE-2023-1778 โ€ผ

This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems.The vulnerability has been addressed by forcing the user to change their default password to a new non-default password.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2327 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2328 โ€ผ

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Combating Kubernetes โ€” the Newest IAM Challenge ๐Ÿ•ด

IT leaders need to ensure Kubernetes clusters don't become a gateway for cybercriminals.

๐Ÿ“– Read

via "Dark Reading".
โค1
โ€ผ CVE-2023-2336 โ€ผ

Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-29255 โ€ผ

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as it may trap when compiling a variation of an anonymous block. IBM X-Force ID: 251991.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-2339 โ€ผ

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

๐Ÿ“– Read

via "National Vulnerability Database".