SysAdmin 24x7
4.34K subscribers
41 photos
2 videos
8 files
6.03K links
Noticias y alertas de seguridad informática.
Chat y contacto:
t.me/sysadmin24x7chat
Download Telegram
Múltiples vulnerabilidades en productos de F5

Fecha de publicación: 02/07/2019
Importancia: 4 - Alta

Recursos afectados: 
BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator), versiones:
14.0.0 - 14.1.0.5;
13.0.0 - 13.1.1.4;
12.1.0 - 12.1.4;
11.5.1 - 11.6.4.
F5 SSL Orchestrator, versiones:
14.0.0;
14.1.0.

Descripción: 
F5 ha publicado múltiples vulnerabilidades del tipo XSS, DoS, inyección de comandos y flujo de tráfico no revelado.

https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/multiples-vulnerabilidades-productos-f5-3
#Android July 2019 #Security Update Patches 33 New Vulnerabilities

Google has started rolling out this month's security updates for its mobile operating system platform to address a total of 33 new security vulnerabilities affecting Android devices, 9 of which have been rated critical in severity.

https://thehackernews.com/2019/07/android-security-update.html
Múltiples vulnerabilidades en iDRAC de Dell EMC

Fecha de publicación: 02/07/2019
Importancia: 4 - Alta

Recursos afectados: 
Dell EMC iDRAC6, versiones anteriores a 2.92;
Dell EMC iDRAC7/iDRAC8, versiones anteriores a 2.61.60.60;
Dell EMC iDRAC9, versiones anteriores a:
3.20.21.20;
3.21.24.22;
3.21.25.22;
3.21.26.22;
3.22.22.22;
3.23.23.23;
3.24.24.24;
3.30.30.30.

Descripción: 
Dell EMC ha detectado tres vulnerabilidades de criticidad alta en múltiples productos de la familia iDRAC. Un atacante remoto podría, ejecutar código arbitrario, saltarse la autenticación o bloquear el sistema.

https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/multiples-vulnerabilidades-idrac-dell-emc
#Debian Security Advisory

DSA-4475-1 #openssl -- security update

https://www.debian.org/security/2019/dsa-4475
#Debian Security Advisor

DSA-4473-1 #rdesktop -- actualización de seguridad

Información adicional:
Se encontraron múltiples problemas de seguridad en el cliente RDP rdesktop que podrían dar lugar a denegación de servicio y a ejecución de código arbitrario.

https://www.debian.org/security/2019/dsa-4473
#VMware Releases Security Advisory for Multiple Products

VMware has released a security advisory to address vulnerabilities affecting multiple products. An attacker could exploit these vulnerabilities to cause a denial-of-service condition.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the VMware Security Advisory VMSA-2019-0009 and apply mitigations or patches, when available.

https://www.us-cert.gov/ncas/current-activity/2019/07/02/vmware-releases-security-advisory-multiple-products
Old known issue in #Firefox allows HTML files to steal other files from victim’s system

Opening an HTML file on Firefox could allow attackers to steal files stored on a victim’s computer due to a weakness in the popular web browser.

https://securityaffairs.co/wordpress/87928/hacking/firefox-flaw-data-theft.html
ACSC Releases Updated Essential Eight Maturity Model

The Australian Cyber Security Centre (ACSC) has released updates to its Essential Eight Maturity Model. The model assists organizations in determining the maturity of their implementation of the Essential Eight—ACSC’s list of the top mitigation strategies to help organizations protect their systems against adversary threats. The model identifies three levels of maturity for each mitigation strategy.

https://www.us-cert.gov/ncas/current-activity/2019/07/05/acsc-releases-updated-essential-eight-maturity-model
#Microsoft #Outlook Security Feature Bypass (CVE-2017-11774)


Vulnerability Description
A security feature bypass vulnerability exists in Microsoft Outlook. The vulnerability is due to improper handling of objects in memory. A remote attacker may exploit this vulnerability by enticing a target user to load a specially crafted HTML file.

https://www.checkpoint.com/defense/advisories/public/2019/cpai-2019-0832.html
All-in-one #Mobile Security Frameworks including #Android and iOS Application Penetration Testing.

-static analysis
-reverse engineering
-dynamic analysis
-network tools
-bypass root & ssl pining
-server side testing

https://hackersonlineclub.com/mobile-security-penetration-testing/
Ubuntu updates for TCP SACK Panic vulnerabilities

Issues have been identified in the way the Linux kernel’s TCP implementation processes Selective Acknowledgement (SACK) options and handles low Maximum Segment Size (MSS) values. These TCP SACK Panic vulnerabilities could expose servers to a denial of service attack, so it is crucial to have systems patched.

https://admin.insights.ubuntu.com/2019/07/05/mitigations-for-tcp-sack-panic-vulnerabilities
Vulnerabilidad en UIoT de HPE

Fecha de publicación: 08/07/2019
Importancia: 4 - Alta

Recursos afectados: 
HPE Universal Internet of Things (UIoT), versiones:
1.6;
1.5;
1.4.2;
1.4.1;
1.4.0;
1.2.4.2.

Descripción: 
HPE ha detectado una vulnerabilidad de criticidad alta en múltiples versiones de UIoT.

https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/vulnerabilidad-uiot-hpe