Forwarded from Una al día
Google Forms como elemento clave en ataques de Phishing
https://unaaldia.hispasec.com/2023/12/google-forms-como-elemento-clave-en-ataques-de-phishing.html?utm_source=rss&utm_medium=rss&utm_campaign=google-forms-como-elemento-clave-en-ataques-de-phishing
https://unaaldia.hispasec.com/2023/12/google-forms-como-elemento-clave-en-ataques-de-phishing.html?utm_source=rss&utm_medium=rss&utm_campaign=google-forms-como-elemento-clave-en-ataques-de-phishing
Una al Día
Google Forms como elemento clave en ataques de Phishing
Los actores detrás de los phishing de BazaCall elevan sus tácticas al emplear Google Forms para dar una apariencia de credibilidad.
Fortinet Releases Security Updates for Multiple Products
Release DateDecember 14, 2023
Fortinet has released security updates to address vulnerabilities in multiple Fortinet products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.
https://www.cisa.gov/news-events/alerts/2023/12/14/fortinet-releases-security-updates-multiple-products
Release DateDecember 14, 2023
Fortinet has released security updates to address vulnerabilities in multiple Fortinet products. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.
https://www.cisa.gov/news-events/alerts/2023/12/14/fortinet-releases-security-updates-multiple-products
Actively Exploited Vulnerability in QNAP VioStor NVR: Fixed, Patches Available
Need to know
As part of our InfectedSlurs research, the SIRT uncovered a vulnerability in QNAP VioStor network video recorder (NVR) devices that is being actively exploited in the wild. The NVR device is a high-performance network surveillance solution for network-based monitoring of IP cameras, video recording, playback, and remote data access. The vulnerability has been given the CVE ID of CVE-2023-47565 with a CVSS v3 score of 8.0.
The vulnerability allows an authenticated attacker to achieve OS command injection with a payload delivered via a POST request to the management interface. In its current configuration, it is utilizing device default credentials in the captured payloads.
https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched
Need to know
As part of our InfectedSlurs research, the SIRT uncovered a vulnerability in QNAP VioStor network video recorder (NVR) devices that is being actively exploited in the wild. The NVR device is a high-performance network surveillance solution for network-based monitoring of IP cameras, video recording, playback, and remote data access. The vulnerability has been given the CVE ID of CVE-2023-47565 with a CVSS v3 score of 8.0.
The vulnerability allows an authenticated attacker to achieve OS command injection with a payload delivered via a POST request to the management interface. In its current configuration, it is utilizing device default credentials in the captured payloads.
https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched
Akamai
Actively Exploited Vulnerability in QNAP VioStor NVR: Fixed, Patches Available | Akamai
When researching the InfectedSlurs botnet, the SIRT uncovered a vulnerability in QNAP VioStor NVR devices being actively exploited in the wild. Get the details.
Múltiples vulnerabilidades en OpenSSH
Fecha 19/12/2023
Importancia 4 - Alta
Recursos Afectados
OpenSSH, versiones anteriores a 9.6.
En las referencias se enlaza una herramienta para escanear servidores o clientes SSH vulnerables a Terrapin Attack.
Descripción
Se ha publicado la versión 9.6 de OpenSSH, que contiene una serie de correcciones de seguridad, destacando 3 vulnerabilidades descubiertas por los investigadores Fabian Bäumer, Marcus Brinkmann y Jörg Schwenk, de la Universidad Ruhr de Bochum, y que se ha denominado Terrapin Attack. La explotación de estas vulnerabilidades podría permitir un ataque MitM que rompiese la integridad del canal seguro de SSH.
Solución
Actualizar OpenSSH a la versión 9.6.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-openssh
Fecha 19/12/2023
Importancia 4 - Alta
Recursos Afectados
OpenSSH, versiones anteriores a 9.6.
En las referencias se enlaza una herramienta para escanear servidores o clientes SSH vulnerables a Terrapin Attack.
Descripción
Se ha publicado la versión 9.6 de OpenSSH, que contiene una serie de correcciones de seguridad, destacando 3 vulnerabilidades descubiertas por los investigadores Fabian Bäumer, Marcus Brinkmann y Jörg Schwenk, de la Universidad Ruhr de Bochum, y que se ha denominado Terrapin Attack. La explotación de estas vulnerabilidades podría permitir un ataque MitM que rompiese la integridad del canal seguro de SSH.
Solución
Actualizar OpenSSH a la versión 9.6.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-openssh
www.incibe.es
Múltiples vulnerabilidades en OpenSSH
Se ha publicado la versión 9.6 de OpenSSH, que contiene una serie de correcciones de seguridad, destac
Múltiples vulnerabilidades en Ivanti
Fecha 19/12/2023
Importancia 4 - Alta
Recursos Afectados
Ivanti Avalanche v6.4.1
Descripción
Ivanti ha publicado 3 vulnerabilidades de severidad alta con un factor de riesgo crítico que podrían provocar un desbordamiento de búfer.
Solución
Actualizar a la versión Ivanti Avalanche 6.4.2 o posteriores.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-ivanti
Fecha 19/12/2023
Importancia 4 - Alta
Recursos Afectados
Ivanti Avalanche v6.4.1
Descripción
Ivanti ha publicado 3 vulnerabilidades de severidad alta con un factor de riesgo crítico que podrían provocar un desbordamiento de búfer.
Solución
Actualizar a la versión Ivanti Avalanche 6.4.2 o posteriores.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-ivanti
www.incibe.es
Múltiples vulnerabilidades en Ivanti
[Actualización 20/12/2023]
Akamai discloses zero-click exploit for Microsoft Outlook
During research into an older Microsoft Outlook privilege escalation vulnerability, Akamai discovered two new flaws that can be chained for a zero-click RCE exploit.
https://www.techtarget.com/searchsecurity/news/366563449/Akamai-discloses-zero-click-exploit-for-Microsoft-Outlook
During research into an older Microsoft Outlook privilege escalation vulnerability, Akamai discovered two new flaws that can be chained for a zero-click RCE exploit.
https://www.techtarget.com/searchsecurity/news/366563449/Akamai-discloses-zero-click-exploit-for-Microsoft-Outlook
Security
Akamai discloses zero-click exploit for Microsoft Outlook
Akamai researcher Ben Barnea examined previous Microsoft Outlook mitigation bypasses and found two new Windows vulnerabilities for a chained exploit.
SysAdmin 24x7
Múltiples vulnerabilidades en Ivanti Fecha 19/12/2023 Importancia 4 - Alta Recursos Afectados Ivanti Avalanche v6.4.1 Descripción Ivanti ha publicado 3 vulnerabilidades de severidad alta con un factor de riesgo crítico que podrían provocar un desbordamiento…
Múltiples vulnerabilidades en Ivanti
Fecha 19/12/2023
Importancia 5 - Crítica
Recursos Afectados
Ivanti Avalanche v6.4.1
Descripción
[Actualización 20/12/2023]
Ivanti ha publicado 20 vulnerabilidades de severidad crítica y alta que podrían provocar daños en la memoria, lo que daría lugar a una denegación de servicio (DoS) o la ejecución de código.
Solución
Actualizar a la versión Ivanti Avalanche 6.4.2 o posteriores.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-ivanti
Fecha 19/12/2023
Importancia 5 - Crítica
Recursos Afectados
Ivanti Avalanche v6.4.1
Descripción
[Actualización 20/12/2023]
Ivanti ha publicado 20 vulnerabilidades de severidad crítica y alta que podrían provocar daños en la memoria, lo que daría lugar a una denegación de servicio (DoS) o la ejecución de código.
Solución
Actualizar a la versión Ivanti Avalanche 6.4.2 o posteriores.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-ivanti
www.incibe.es
Múltiples vulnerabilidades en Ivanti
[Actualización 20/12/2023]
Apple Releases Security Updates for Multiple Products
Release Date December 20, 2023
Apple has released security updates to address vulnerabilities in Safari, iOS, iPadOS, and macOS Sonoma. A cyber threat actor could exploit one of these vulnerabilities to obtain sensitive information.
https://www.cisa.gov/news-events/alerts/2023/12/20/apple-releases-security-updates-multiple-products
Release Date December 20, 2023
Apple has released security updates to address vulnerabilities in Safari, iOS, iPadOS, and macOS Sonoma. A cyber threat actor could exploit one of these vulnerabilities to obtain sensitive information.
https://www.cisa.gov/news-events/alerts/2023/12/20/apple-releases-security-updates-multiple-products
Múltiples vulnerabilidades en Unified OSS Console de HPE
Fecha 22/12/2023
Importancia 5 - Crítica
Recursos Afectados
HPE Unified OSS Console (UOC), versiones anteriores a v3.1.0.
Descripción
El equipo de respuesta de seguridad de productos de HPE ha informado que, una vulnerabilidad de severidad crítica y dos vulnerabilidades de severidad alta ya reportadas, afectan a uno de sus productos. La explotación de estas vulnerabilidades podría permitir a un atacante remoto evadir las restricciones de acceso, realizar una ejecución arbitraria de código, evadir la autenticación, comprometer la integridad del sistema, y desbordar el búfer.
Solución
HPE ha resuelto las vulnerabilidades reportadas en la versión 3.1.0.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-unified-oss-console-de-hpe
Fecha 22/12/2023
Importancia 5 - Crítica
Recursos Afectados
HPE Unified OSS Console (UOC), versiones anteriores a v3.1.0.
Descripción
El equipo de respuesta de seguridad de productos de HPE ha informado que, una vulnerabilidad de severidad crítica y dos vulnerabilidades de severidad alta ya reportadas, afectan a uno de sus productos. La explotación de estas vulnerabilidades podría permitir a un atacante remoto evadir las restricciones de acceso, realizar una ejecución arbitraria de código, evadir la autenticación, comprometer la integridad del sistema, y desbordar el búfer.
Solución
HPE ha resuelto las vulnerabilidades reportadas en la versión 3.1.0.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-unified-oss-console-de-hpe
www.incibe.es
Múltiples vulnerabilidades en Unified OSS Console de HPE
El equipo de respuesta de seguridad de productos de HPE ha informado que, una vulnerabilidad de severi
Apple releases macOS 14.2.1 Sonoma and iOS 17.2.1 updates
Apple has released the macOS 14.2.1 Sonoma and iOS 17.2.1 updates. The new software with bug fixes, and one security fix for Macs.
macOS 14.2.1 Sonoma update
macOS 14.2.1 fixes a loophole that is related to WindowServer. The security vulnerability, which has been tracked under CVE-2023-42940, contained an exploit that may share incorrect content when a user shares their screen. The bug, which has been described as a session rendering issue, was addressed with improved session tracking. Apple has credited software developer Craig Hockenberry for reporting the bug to it.
https://www.ghacks.net/2023/12/20/apple-releases-macos-14-2-1-sonoma-and-ios-17-2-1-updates/
Apple has released the macOS 14.2.1 Sonoma and iOS 17.2.1 updates. The new software with bug fixes, and one security fix for Macs.
macOS 14.2.1 Sonoma update
macOS 14.2.1 fixes a loophole that is related to WindowServer. The security vulnerability, which has been tracked under CVE-2023-42940, contained an exploit that may share incorrect content when a user shares their screen. The bug, which has been described as a session rendering issue, was addressed with improved session tracking. Apple has credited software developer Craig Hockenberry for reporting the bug to it.
https://www.ghacks.net/2023/12/20/apple-releases-macos-14-2-1-sonoma-and-ios-17-2-1-updates/
ghacks.net
Apple releases macOS 14.2.1 Sonoma and iOS 17.2.1 updates
Apple releases macOS 14.2.1 Sonoma update to fix a security issue. iOS 17.2.1 update is also available with mysterious bug fixes.
Windows CLFS and five exploits used by ransomware operators
https://securelist.com/windows-clfs-exploits-ransomware/111560/
https://securelist.com/windows-clfs-exploits-ransomware/111560/
Securelist
Windows CLFS and five exploits used by ransomware operators
We had never seen so many CLFS driver exploits being used in active attacks before, and then suddenly there are so many of them captured in just one year. Is there something wrong with the CLFS driver? Are all these vulnerabilities similar? These questions…
[CA8562] ESET Customer Advisory: Improper following of a certificate's chain of trust in ESET security products fixed
Summary
ESET was made aware of a vulnerability in its SSL/TLS protocol scanning feature, which is available in ESET products listed in the Affected products section below. This vulnerability would cause a browser to trust a site with a certificate signed with an obsolete algorithm that should not be trusted.
https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed
Summary
ESET was made aware of a vulnerability in its SSL/TLS protocol scanning feature, which is available in ESET products listed in the Affected products section below. This vulnerability would cause a browser to trust a site with a certificate signed with an obsolete algorithm that should not be trusted.
https://support.eset.com/en/ca8562-eset-customer-advisory-improper-following-of-a-certificates-chain-of-trust-in-eset-security-products-fixed
Google addressed a new actively exploited Chrome zero-day
Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser.
https://securityaffairs.com/156231/security/google-addressed-a-new-actively-exploited-chrome-zero-day.html
Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser.
https://securityaffairs.com/156231/security/google-addressed-a-new-actively-exploited-chrome-zero-day.html
Security Affairs
Google addressed a new actively exploited Chrome zero-day
Google has released emergency updates to address a new actively exploited zero-day vulnerability in the Chrome browser.
Dual Privilege Escalation Chain: Exploiting Monitoring and Service Mesh Configurations and Privileges in GKE to Gain Unauthorized Access in Kubernetes
This article examines two specific issues in Google Kubernetes Engine (GKE). While each issue might not result in significant damage on its own, when combined they create an opportunity for an attacker who already has access to a Kubernetes cluster to escalate their privileges. This article serves as a crucial resource for Kubernetes users and administrators, offering insights on safeguarding their clusters from potential attacks.
https://unit42.paloaltonetworks.com/google-kubernetes-engine-privilege-escalation-fluentbit-anthos/
This article examines two specific issues in Google Kubernetes Engine (GKE). While each issue might not result in significant damage on its own, when combined they create an opportunity for an attacker who already has access to a Kubernetes cluster to escalate their privileges. This article serves as a crucial resource for Kubernetes users and administrators, offering insights on safeguarding their clusters from potential attacks.
https://unit42.paloaltonetworks.com/google-kubernetes-engine-privilege-escalation-fluentbit-anthos/
Unit 42
Dual Privilege Escalation Chain: Exploiting Monitoring and Service Mesh Configurations and Privileges in GKE to Gain Unauthorized…
Two issues in Google Kubernetes Engine (GKE) create a privilege escalation chain. We examine second-stage attacks which exploit the container environment.
Múltiples vulnerabilidades en Juniper Secure Analytics
Fecha 29/12/2023
Importancia 5 - Crítica
Recursos Afectados
Juniper Secure Analytics, versiones hasta 7.5.0 UP7.
Descripción
Se han reportado 18 vulnerabilidades en Juniper Secure Analytics, de las cuales: 2 son de severidad baja, 7 de severidad media, 7 de severidad alta, y 2 de severidad crítica.
Solución
Se han resuelto las vulnerabilidades reportadas en Juniper Secure Analytics versión 7.5.0 UP7 IF03.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-juniper-secure-analytics
Fecha 29/12/2023
Importancia 5 - Crítica
Recursos Afectados
Juniper Secure Analytics, versiones hasta 7.5.0 UP7.
Descripción
Se han reportado 18 vulnerabilidades en Juniper Secure Analytics, de las cuales: 2 son de severidad baja, 7 de severidad media, 7 de severidad alta, y 2 de severidad crítica.
Solución
Se han resuelto las vulnerabilidades reportadas en Juniper Secure Analytics versión 7.5.0 UP7 IF03.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-juniper-secure-analytics
www.incibe.es
Múltiples vulnerabilidades en Juniper Secure Analytics
Se han reportado 18 vulnerabilidades en Juniper Secure Analytics, de las cuales: 2 son de severidad ba
Comunicación del servidor no autenticada en D-Link D-View 8
Fecha 29/12/2023
Importancia 5 - Crítica
Recursos Afectados
D-View 8, versiones 2.0.2.89 y anteriores.
Descripción
El equipo de investigación de Tenable ha publicado una vulnerabilidad crítica que afecta al software de administración de red D-View 8 del fabricante D-Link.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/comunicacion-del-servidor-no-autenticada-en-d-link-d-view-8
Fecha 29/12/2023
Importancia 5 - Crítica
Recursos Afectados
D-View 8, versiones 2.0.2.89 y anteriores.
Descripción
El equipo de investigación de Tenable ha publicado una vulnerabilidad crítica que afecta al software de administración de red D-View 8 del fabricante D-Link.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/comunicacion-del-servidor-no-autenticada-en-d-link-d-view-8
www.incibe.es
Comunicación del servidor no autenticada en D-Link D-View 8
El equipo de investigación de Tenable ha publicado una vulnerabilidad crítica que afecta al softwa
Juniper Releases Security Advisory for Juniper Secure Analytics
Release DateJanuary 02, 2024
Juniper released a security advisory to address multiple vulnerabilities affecting Juniper Secure Analytics. A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the Juniper advisory JSA75636 and apply the necessary updates.
https://www.cisa.gov/news-events/alerts/2024/01/02/juniper-releases-security-advisory-juniper-secure-analytics
https://supportportal.juniper.net/s/article/2023-12-Security-Bulletin-JSA-Series-Multiple-vulnerabilities-resolved
Release DateJanuary 02, 2024
Juniper released a security advisory to address multiple vulnerabilities affecting Juniper Secure Analytics. A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system.
CISA encourages users and administrators to review the Juniper advisory JSA75636 and apply the necessary updates.
https://www.cisa.gov/news-events/alerts/2024/01/02/juniper-releases-security-advisory-juniper-secure-analytics
https://supportportal.juniper.net/s/article/2023-12-Security-Bulletin-JSA-Series-Multiple-vulnerabilities-resolved
Forwarded from Una al día
Descubierta nueva vulnerabilidad Terrapin que pone en riesgo la seguridad de las conexiones SSH
https://unaaldia.hispasec.com/2024/01/descubierta-nueva-vulnerabilidad-terrapin-que-pone-en-riesgo-la-seguridad-de-las-conexiones-ssh.html?utm_source=rss&utm_medium=rss&utm_campaign=descubierta-nueva-vulnerabilidad-terrapin-que-pone-en-riesgo-la-seguridad-de-las-conexiones-ssh
https://unaaldia.hispasec.com/2024/01/descubierta-nueva-vulnerabilidad-terrapin-que-pone-en-riesgo-la-seguridad-de-las-conexiones-ssh.html?utm_source=rss&utm_medium=rss&utm_campaign=descubierta-nueva-vulnerabilidad-terrapin-que-pone-en-riesgo-la-seguridad-de-las-conexiones-ssh
Una al Día
Descubierta nueva vulnerabilidad Terrapin que pone en riesgo la seguridad de las conexiones SSH
Terrapin representa el "primer ataque de truncamiento de prefijo prácticamente explotable" sobre el protocolo SSH.
Hacker hijacks Orange Spain RIPE account to cause BGP havoc
Orange Spain suffered an internet outage today after a hacker breached the company's RIPE account to misconfigure BGP routing and an RPKI configuration.
The routing of traffic on the internet is handled by Border Gateway Protocol (BGP), which allows organizations to associate their IP addresses with autonomous system (AS) numbers and advertise them to other routers they are connected to, known as their peers.
These BGP advertisements create a routing table that propagates to all other edge routers on the internet, allowing networks to know the best route to send traffic to a particular IP address.
https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/
Orange Spain suffered an internet outage today after a hacker breached the company's RIPE account to misconfigure BGP routing and an RPKI configuration.
The routing of traffic on the internet is handled by Border Gateway Protocol (BGP), which allows organizations to associate their IP addresses with autonomous system (AS) numbers and advertise them to other routers they are connected to, known as their peers.
These BGP advertisements create a routing table that propagates to all other edge routers on the internet, allowing networks to know the best route to send traffic to a particular IP address.
https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/
BleepingComputer
Hacker hijacks Orange Spain RIPE account to cause BGP havoc
Orange Spain suffered an internet outage today after a hacker breached the company's RIPE account to misconfigure BGP routing and an RPKI configuration.
Three New Malicious PyPI Packages Deploy CoinMiner on Linux Devices
Affected platforms: Linux
Affected parties: Linux users that have these malicious packages installed
Impact: Latency in device performance
Severity level: High
[...]
Fortinet Protections
FortiGuard AntiVirus detects the malicious files identified in this report as
unmi.sh: Linux/Agent.4EFF!tr
modularseven-1.0/modularseven/processor.py: Python/Agent.5337!tr
driftme-1.0/driftme/processor.py: Python/Agent.5337!tr
catme-1.0/catme/processor.py: Python/Agent.5337!tr
tmp/X: Riskware/CoinMiner
[...]
https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices
Affected platforms: Linux
Affected parties: Linux users that have these malicious packages installed
Impact: Latency in device performance
Severity level: High
[...]
Fortinet Protections
FortiGuard AntiVirus detects the malicious files identified in this report as
unmi.sh: Linux/Agent.4EFF!tr
modularseven-1.0/modularseven/processor.py: Python/Agent.5337!tr
driftme-1.0/driftme/processor.py: Python/Agent.5337!tr
catme-1.0/catme/processor.py: Python/Agent.5337!tr
tmp/X: Riskware/CoinMiner
[...]
https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices
Fortinet Blog
Three New Malicious PyPI Packages Deploy CoinMiner on Linux Devices
FortiGuard Labs cover the attack phases of three new PyPI packages that bear a resemblance to the culturestreak PyPI package discovered earlier this year. Learn more.…
Critical Remote Code Execution Vulnerability in Ivanti’s Endpoint Management Software
January 4, 2024
Ivanti has issued a warning and fix for a critical remote code execution (RCE) vulnerability found in its Endpoint Management software (EPM). The vulnerability, identified as CVE-2023-39366, could have allowed unauthenticated attackers to gain control over devices enrolled in the EPM or the core server itself.
https://vulnera.com/newswire/critical-remote-code-execution-vulnerability-in-ivantis-endpoint-management-software/
January 4, 2024
Ivanti has issued a warning and fix for a critical remote code execution (RCE) vulnerability found in its Endpoint Management software (EPM). The vulnerability, identified as CVE-2023-39366, could have allowed unauthenticated attackers to gain control over devices enrolled in the EPM or the core server itself.
https://vulnera.com/newswire/critical-remote-code-execution-vulnerability-in-ivantis-endpoint-management-software/
VULNERA - Vulnerability Management. Simplified.
Critical Remote Code Execution Vulnerability in Ivanti’s Endpoint Management Software - VULNERA
Ivanti has issued a warning and fix for a critical remote code execution (RCE) vulnerability found in its Endpoint Management software (EPM).