Cisco Releases Security Updates for Multiple Products
Original release date: April 14, 2022
Cisco has released security updates to address vulnerabilities in multiple Cisco products. An attacker could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the Cisco Security Advisories page and apply the necessary updates.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/14/cisco-releases-security-updates-multiple-products
Original release date: April 14, 2022
Cisco has released security updates to address vulnerabilities in multiple Cisco products. An attacker could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the Cisco Security Advisories page and apply the necessary updates.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/14/cisco-releases-security-updates-multiple-products
www.cisa.gov
Cisco Releases Security Updates for Multiple Products | CISA
Cisco has released security updates to address vulnerabilities in multiple Cisco products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Cisco Security…
Auth bypass flaw in Cisco Wireless LAN Controller Software allows device takeover
Cisco fixed a critical flaw in Cisco Wireless LAN Controller (WLC) that could allow an unauthenticated, remote attacker to take control affected devices.
Cisco has released security patches to fix a critical vulnerability (CVSS score 10), tracked as CVE-2022-20695, in Cisco Wireless LAN Controller (WLC). A remote, unauthenticated attacker could exploit the flaw to bypass authentication and log in to the device through the management interface.
https://securityaffairs.co/wordpress/130217/security/auth-bypass-cisco-wireless-lan-controller.html
Cisco fixed a critical flaw in Cisco Wireless LAN Controller (WLC) that could allow an unauthenticated, remote attacker to take control affected devices.
Cisco has released security patches to fix a critical vulnerability (CVSS score 10), tracked as CVE-2022-20695, in Cisco Wireless LAN Controller (WLC). A remote, unauthenticated attacker could exploit the flaw to bypass authentication and log in to the device through the management interface.
https://securityaffairs.co/wordpress/130217/security/auth-bypass-cisco-wireless-lan-controller.html
Security Affairs
Auth bypass flaw in Cisco Wireless LAN Controller Software allows device takeover - Security Affairs
Cisco fixed a critical flaw in Cisco Wireless LAN Controller (WLC) that could allow an unauthenticated, remote attacker to take control affected devices.
Workaround for security issue in 7-Zip until it is fixed.
Recent versions of the open source archiver 7-Zip have a vulnerability that has not been fixed yet. Successful exploitation of the vulnerability allows privilege escalation and the execution of commands; it appears that the issue can be exploited locally only.
ttps://www.ghacks.net/2022/04/18/workaround-for-security-issue-in-7-zip-until-it-is-fixed/
Recent versions of the open source archiver 7-Zip have a vulnerability that has not been fixed yet. Successful exploitation of the vulnerability allows privilege escalation and the execution of commands; it appears that the issue can be exploited locally only.
ttps://www.ghacks.net/2022/04/18/workaround-for-security-issue-in-7-zip-until-it-is-fixed/
When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops
ESET researchers discover multiple vulnerabilities in various Lenovo laptop models that allow an attacker with admin privileges to expose the user to firmware-level malware
https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/
ESET researchers discover multiple vulnerabilities in various Lenovo laptop models that allow an attacker with admin privileges to expose the user to firmware-level malware
https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/
WeLiveSecurity
When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops
ESET research discovers vulnerabilities in Lenovo consumer laptop models that allow attackers with admin rights to expose users to firmware-level malware.
Oracle Releases April 2022 Critical Patch Update
Original release date: April 19, 2022
Oracle has released its Critical Patch Update for April 2022 to address 520 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the Oracle April 2022 Critical Patch Update and apply the necessary updates.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/19/oracle-releases-april-2022-critical-patch-update
Original release date: April 19, 2022
Oracle has released its Critical Patch Update for April 2022 to address 520 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the Oracle April 2022 Critical Patch Update and apply the necessary updates.
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/19/oracle-releases-april-2022-critical-patch-update
www.cisa.gov
Oracle Releases April 2022 Critical Patch Update | CISA
Oracle has released its Critical Patch Update for April 2022 to address 520 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators…
Múltiples vulnerabilidades en el core de Drupal 9
Fecha de publicación: 21/04/2022
Importancia: 3 - Media
Recursos afectados:
Drupal, versiones anteriores a la 9.3.12 y 9.2.18.
Las versiones de Drupal 8 y de Drupal 9, anteriores a la 9.2.x, se encuentran al final de su vida útil y ya no reciben cobertura de seguridad.
Descripción:
Se han publicado dos vulnerabilidades de severidad media, que podrían afectar al core de Drupal.
https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/multiples-vulnerabilidades-el-core-drupal-9
Fecha de publicación: 21/04/2022
Importancia: 3 - Media
Recursos afectados:
Drupal, versiones anteriores a la 9.3.12 y 9.2.18.
Las versiones de Drupal 8 y de Drupal 9, anteriores a la 9.2.x, se encuentran al final de su vida útil y ya no reciben cobertura de seguridad.
Descripción:
Se han publicado dos vulnerabilidades de severidad media, que podrían afectar al core de Drupal.
https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/multiples-vulnerabilidades-el-core-drupal-9
INCIBE-CERT
Múltiples vulnerabilidades en el core de Drupal 9
Se han publicado dos vulnerabilidades de severidad media, que podrían afectar al core de Drupal.
Jira Security Advisory 2022-04-20
Summary
CVE-2022-0540 - Authentication bypass in Seraph
Severity: critical
Fixed Jira Versions
8.13.x >= 8.13.18
8.20.x >= 8.20.6
All versions >= 8.22.0
https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html
Summary
CVE-2022-0540 - Authentication bypass in Seraph
Severity: critical
Fixed Jira Versions
8.13.x >= 8.13.18
8.20.x >= 8.20.6
All versions >= 8.22.0
https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html
April 25, 2022—KB5011831 (OS Builds 19042.1682, 19043.1682, and 19044.1682) Preview
https://support.microsoft.com/en-us/topic/april-25-2022-kb5011831-os-builds-19042-1682-19043-1682-and-19044-1682-preview-fe4ff411-d25a-4185-aabb-8bc66e9dbb6c
Windows 10 KB5011831 update released with 26 bug fixes, improvements
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5011831-update-released-with-26-bug-fixes-improvements/
https://support.microsoft.com/en-us/topic/april-25-2022-kb5011831-os-builds-19042-1682-19043-1682-and-19044-1682-preview-fe4ff411-d25a-4185-aabb-8bc66e9dbb6c
Windows 10 KB5011831 update released with 26 bug fixes, improvements
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5011831-update-released-with-26-bug-fixes-improvements/
BleepingComputer
Windows 10 KB5011831 update released with 26 bug fixes, improvements
Microsoft has released the optional KB5011831 Preview cumulative update for Windows 10 20H2, Windows 10 21H1, and Windows 10 21H2 that fixes 26 bugs.
Múltiples vulnerabilidades en dispositivos NAS de QNAP
Fecha de publicación: 26/04/2022
Importancia: 4 - Alta
Recursos afectados:
Dispositivos NAS de QNAP con versiones:
QTS 5.0.x y posteriores
QTS 4.5.4 y posteriores
QTS 4.3.6 y posteriores
QTS 4.3.4 y posteriores
QTS 4.3.3 y posteriores
QTS 4.2.6 y posteriores
QuTS hero h5.0.x y posteriores
QuTS hero h4.5.4 y posteriores
QuTScloud c5.0.x
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/multiples-vulnerabilidades-dispositivos-nas-qnap
Fecha de publicación: 26/04/2022
Importancia: 4 - Alta
Recursos afectados:
Dispositivos NAS de QNAP con versiones:
QTS 5.0.x y posteriores
QTS 4.5.4 y posteriores
QTS 4.3.6 y posteriores
QTS 4.3.4 y posteriores
QTS 4.3.3 y posteriores
QTS 4.2.6 y posteriores
QuTS hero h5.0.x y posteriores
QuTS hero h4.5.4 y posteriores
QuTScloud c5.0.x
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/multiples-vulnerabilidades-dispositivos-nas-qnap
INCIBE
Múltiples vulnerabilidades en dispositivos NAS de QNAP
PowerShell Elevation of Privilege Vulnerability
CVE-2022-26788
Released: Apr 12, 2022
Last updated: Apr 27, 2022
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26788
PowerShell Elevation of Privilege Vulnerability.
CNA: Microsoft Corporation
Base Score: 7.8 HIGH
https://nvd.nist.gov/vuln/detail/CVE-2022-26788#vulnCurrentDescriptionTitle
CVE-2022-26788
Released: Apr 12, 2022
Last updated: Apr 27, 2022
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26788
PowerShell Elevation of Privilege Vulnerability.
CNA: Microsoft Corporation
Base Score: 7.8 HIGH
https://nvd.nist.gov/vuln/detail/CVE-2022-26788#vulnCurrentDescriptionTitle
1Password syncing went down for a few hours today during a database upgrade.
https://www.theverge.com/2022/4/27/23045469/1password-outage-password-manager-security-cloud-storage
https://www.theverge.com/2022/4/27/23045469/1password-outage-password-manager-security-cloud-storage
The Verge
1Password syncing went down for a few hours today during a database upgrade
The password manager still (mostly) worked while offline
QNAP warns users to disable AFP until it fixes critical bugs.
Taiwanese corporation QNAP has asked customers this week to disable the AFP file service protocol on their network-attached storage (NAS) appliances until it fixes multiple critical Netatalk vulnerabilities.
https://www.bleepingcomputer.com/news/security/qnap-warns-users-to-disable-afp-until-it-fixes-critical-bugs/
Taiwanese corporation QNAP has asked customers this week to disable the AFP file service protocol on their network-attached storage (NAS) appliances until it fixes multiple critical Netatalk vulnerabilities.
https://www.bleepingcomputer.com/news/security/qnap-warns-users-to-disable-afp-until-it-fixes-critical-bugs/
BleepingComputer
QNAP warns users to disable AFP until it fixes critical bugs
Taiwanese corporation QNAP has asked customers this week to disable the AFP file service protocol on their network-attached storage (NAS) appliances until it fixes multiple critical Netatalk vulnerabilities.
VirusTotal debunks claims of a serious vulnerability in Google-owned antivirus service.
https://portswigger.net/daily-swig/virustotal-debunks-claims-of-a-serious-vulnerability-in-google-owned-antivirus-service
https://portswigger.net/daily-swig/virustotal-debunks-claims-of-a-serious-vulnerability-in-google-owned-antivirus-service
The Daily Swig | Cybersecurity news and views
VirusTotal debunks claims of a serious vulnerability in Google-owned antivirus service
Claims that researchers were able to execute commands within the antivirus platform have been questioned
Forwarded from Una al día
Inyecciones de malware en el gestor de contraseñas KeePass
https://unaaldia.hispasec.com/2022/04/inyecciones-de-malware-en-el-gestor-de-contrasenas-keepass.html
https://unaaldia.hispasec.com/2022/04/inyecciones-de-malware-en-el-gestor-de-contrasenas-keepass.html
Una al Día
Inyecciones de malware en el gestor de contraseñas KeePass
Investigadores de ESET Research han localizado versiones troyanizadas del popular gestor de contraseñas KeePass.
Microsoft Patches Pair of Dangerous Vulnerabilities in Azure PostgreSQL.
Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.
Microsoft has patched a dangerous pair of vulnerabilities in its Azure Database for PostgreSQL Flexible Server that gave attackers unauthorized cross-account access to databases in cloud hosted environments.
https://www.darkreading.com/cloud/microsoft-patches-pair-of-dangerous-vulnerabilities-in-azure-postgresql
Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.
Microsoft has patched a dangerous pair of vulnerabilities in its Azure Database for PostgreSQL Flexible Server that gave attackers unauthorized cross-account access to databases in cloud hosted environments.
https://www.darkreading.com/cloud/microsoft-patches-pair-of-dangerous-vulnerabilities-in-azure-postgresql
Darkreading
Microsoft Patches Pair of Dangerous Vulnerabilities in Azure PostgreSQL
Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.
CISCO corrige vulnerabilidades en dispositivos ASA, FTD y FMC
Fecha de publicación: 29/04/2022
Importancia: 4 - Alta
Descripción:
Cisco ha publicado varias vulnerabilidades de severidad alta de tipo denegación de servicio, desbordamiento de pila, divulgación de información, escalada de privilegios, y bypass de seguridad en la carga de archivos que afectan a dispositivos con el software ASA, FTD y FMC.
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/cisco-corrige-vulnerabilidades-dispositivos-asa-ftd-y-fmc
Fecha de publicación: 29/04/2022
Importancia: 4 - Alta
Descripción:
Cisco ha publicado varias vulnerabilidades de severidad alta de tipo denegación de servicio, desbordamiento de pila, divulgación de información, escalada de privilegios, y bypass de seguridad en la carga de archivos que afectan a dispositivos con el software ASA, FTD y FMC.
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/cisco-corrige-vulnerabilidades-dispositivos-asa-ftd-y-fmc
INCIBE
CISCO corrige vulnerabilidades en dispositivos ASA, FTD y FMC
Vulnerable plugins plague the CMS website security landscape.
https://www.zdnet.com/article/vulnerable-plugins-default-configurations-plague-the-website-security-landscape/
https://www.zdnet.com/article/vulnerable-plugins-default-configurations-plague-the-website-security-landscape/
ZDNET
Vulnerable plugins plague the CMS website security landscape
Backdoors, card skimming, and spam are also common factors in website compromise.
Atlassian: Two-week-long cloud outage impacted 775 customers.
Atlassian says that this month's two-week-long cloud outage has impacted almost double the number of customers it initially estimated after learning of the incident.
https://www.bleepingcomputer.com/news/technology/atlassian-two-week-long-cloud-outage-impacted-775-customers/
Atlassian says that this month's two-week-long cloud outage has impacted almost double the number of customers it initially estimated after learning of the incident.
https://www.bleepingcomputer.com/news/technology/atlassian-two-week-long-cloud-outage-impacted-775-customers/
BleepingComputer
Atlassian doubles the number of orgs affected by two week outage
Atlassian says that this month's two-week-long cloud outage has impacted almost double the number of customers it initially estimated after learning of the incident.
Vulnerabilidades críticas en DSM y SRM de Synology
Fecha de publicación: 03/05/2022
Importancia: 5 - Crítica
Recursos afectados:
Software para los NAS (DSM) y los rúteres (SRM):
DSM, versiones 7.1, 7.0 y 6.2;
Firmware, versión VS 2.3;
SRM, versión 1.2.
Descripción:
Synology ha publicado varias vulnerabilidades de severidad crítica que afectan al software DSM y SRM, las cuales podrían permitir a un atacante ejecutar código arbitrario u obtener información confidencial.
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/vulnerabilidades-criticas-dsm-y-srm-synology
Fecha de publicación: 03/05/2022
Importancia: 5 - Crítica
Recursos afectados:
Software para los NAS (DSM) y los rúteres (SRM):
DSM, versiones 7.1, 7.0 y 6.2;
Firmware, versión VS 2.3;
SRM, versión 1.2.
Descripción:
Synology ha publicado varias vulnerabilidades de severidad crítica que afectan al software DSM y SRM, las cuales podrían permitir a un atacante ejecutar código arbitrario u obtener información confidencial.
https://www.incibe.es/protege-tu-empresa/avisos-seguridad/vulnerabilidades-criticas-dsm-y-srm-synology
Ejecución remota de código en switches de Aruba
Fecha de publicación: 04/05/2022
Importancia: 5 - Crítica
Descripción:
El equipo de investigación de Armis ha descubierto múltiples vulnerabilidades de desbordamiento de búfer basado en memoria dinámica (heap) en varios dispositivos de Aruba que podría permitir a un atacante remoto la ejecución de código arbitrario en el dispositivo afectado.
https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/ejecucion-remota-codigo-switches-aruba
Fecha de publicación: 04/05/2022
Importancia: 5 - Crítica
Descripción:
El equipo de investigación de Armis ha descubierto múltiples vulnerabilidades de desbordamiento de búfer basado en memoria dinámica (heap) en varios dispositivos de Aruba que podría permitir a un atacante remoto la ejecución de código arbitrario en el dispositivo afectado.
https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/ejecucion-remota-codigo-switches-aruba
INCIBE-CERT
Ejecución remota de código en switches de Aruba
El equipo de investigación de Armis ha descubierto múltiples vulnerabilidades de desbordamiento de búfer basado en memoria dinámica (heap) en varios dispositivos de Aruba que podría permitir a un
Security Advisory Description
Undisclosed requests may bypass iControl REST authentication. (CVE-2022-1388)
Impact
This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
https://support.f5.com/csp/article/K23605346
Undisclosed requests may bypass iControl REST authentication. (CVE-2022-1388)
Impact
This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
https://support.f5.com/csp/article/K23605346