Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

RSS FEEDS

Synology rolls out patches for critical security bugs

Thursday, 5 January, 2023

Synology had published two new critical advisories. One of them describes an internally discovered vulnerability affecting Synology VPN Plus Server, which turns routers into an advanced VPN server. 

 

The security hole, tracked as CVE-2022-43931, is an out-of-bounds write issue in the remote desktop functionality of VPN Plus Server. It can allow a remote attacker to execute arbitrary commands.

 

Multiple Vulnerabilities in Firefox, Firefox ESR, and in Thunderbird

Monday, 19 December, 2022

Mozilla has released critical security updates for Firefox, Firefox ESR, and Thunderbird, addressing multiple vulnerabilities. Most severe of discovered vulnerabilities could lead to memory corruption and arbitrary code execution on successful exploitation.

CVE/Vulnerability

Affected  

Products

Description 

Severity

Exploitable

SAP Releases December 2022 Security

Monday, 19 December, 2022

SAP released twenty new and updated Security Notes on its December Patch Day, including the notes that were released or updated since last Patch Tuesday. This includes five Hot-News Notes and five High Priority Notes. The remaining security notes that SAP announced on December 2022 Security Patch Day deal with medium-severity vulnerabilities in Disclosure Management, NetWeaver, Solutions Manager, BusinessObjects, Sourcing, and Contract Lifecycle Management.

CVE/Vulnerability

Cisco Disclosed High-Severity Flaw in its IP phones

Thursday, 15 December, 2022

Cisco disclosed a high-severity vulnerability, tracked as CVE-2022-20968, impacting its IP Phone 7800 and 8800 Series. A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. 

This vulnerability is due to insufficient input validation of received Cisco Discovery Protocol packets. An attacker could exploit this vulnerability by sending crafted Cisco Discovery Protocol traffic to an affected device. 

Exploitable - Heap - Based Buffer Overflow Vulnerability in FortiOS sslvpnd

Tuesday, 13 December, 2022

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. As per Fortinet this vulnerability is exploited in the wild. Successful exploitation could allow unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

 

 

CVE/Vulnerability

Description

Fortinet Patches High-Severity Authentication Bypass Vulnerability in Forti-OS-PROXY

Sunday, 11 December, 2022

A vulnerability found in Fortinet FortiOS and FortiProxy. CVE-2022-35843 tracked as, authentication bypass was identified in the SSH login component of FortiOS. The bug can only be triggered when Radius authentication is used. The manipulation with an unknown input leads to a authentication bypass by assumed-immutable data vulnerability. CWE is classifying the issue as CWE-302. The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker. 

Multiple High Vulnerabilities in Google Chrome

Monday, 5 December, 2022

Google has released a security update for its chrome browser used in windows, Mac and Linux remediating 28 vulnerabilities among which 8 are rated as high and 20 are medium by Chrome security severity, these vulnerabilities are related to memory safety bugs, including one out-of-bound write issue. 

 

A new vulnerability related to chromium-based browser has been released by google, which is vulnerable to arbitrary code execution or escape the browser’s security sandbox. The exploit for this vulnerability CVE-2022-4262 is already exist and widely in use. 

 

Actively Exploited Vulnerability in Google Chrome

Tuesday, 29 November, 2022

Google has released an emergency update to fix the actively exploited zeroday vulnerability in its Chrome web browser. The exploited vulnerability is (CVE2022-4135) described as a heap buffer overflow in the GPU component.

 

The vulnerability allows remote attacker to potentially perform a sandbox escape via a crafted HTML page. This means, malicious contents can bypass sandboxed environments to execute arbitrary commands on the victim machine. 

 

Atlassian released a patch to address two critical flaws affecting Bitbucket Server, Data Centre & Crowd products

Monday, 21 November, 2022

Atlassian released a patch to address two critical flaws affecting Bitbucket Server, Data Centre & Crowd products.

 

The first weakness (CVE-2022-43781) is described as a case of command injection using environment variables in the software, which could allow an adversary with permission to control their username to gain code execution on the affected system.

 

Multiple security vulnerabilities in F5 BIG-IP and BIG-IQ devices

Monday, 21 November, 2022

Multiple security vulnerabilities have been disclosed in F5 BIG-IP and BIG-IQ devices. Below are the addressed vulnerabilities:

 

CVE-2022-41622: A Cross-Site request forgery (CSRF) vulnerability through iControl SOAP, leading to unauthenticated remote code execution. Successful exploitation allow attacker to gain persistent root access to the device management interface. As per F5, if exploited, the vulnerability can compromise the complete system.

 

Zoom security advisories for multiple high severity vulnerabilities

Monday, 21 November, 2022

Zoom released security advisories for multiple high severity vulnerabilities related to Zoom client. Below are the addressed vulnerabilities: 

 

CVE-2022-28766: the vulnerability is related to DLL injection in windows 32-bit zoom clients. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of zoom client.

 

Microsoft Exchange Zero Day Exploitable Vulnerabilities

Thursday, 10 November, 2022

There are two Zero-Day exploitable vulnerabilities in Microsoft Exchange, CVE-2022-41040 is an elevation of privilege vulnerability and CVE-2022-41082 is allowing Remote Code Execution (RCE) when PowerShell is accessible to the attacker. Successful exploitation may give privilege to attacker to execute commands which may allow exfiltration of data and lateral movement to internal systems. 

 

Cisco Release Patches for Multiple Vulnerabilities

Sunday, 6 November, 2022

Cisco release patches for Identity services engine cross-site request forgery / services engine insufficient access control Identity Services Engine (ISE).

The most severe of these issues is CVE-2022-2096, a cross-site request forgery (CSRF) flaw in Identity Services Engine (ISE) that could allow an unauthenticated, remote attacker to perform arbitrary actions on a vulnerable device.

Exploitable Vulnerability in SQLite Database Library

Monday, 31 October, 2022

An Integer Overflow vulnerability has been discovered in the SQLite database library. The vulnerability is identified as CVE-2022-35737 and rated with high severity. 

 

On exploitation of the vulnerability, the attacker can execute arbitrary code and/or Denial of Service attack on vulnerable systems. Mainly 64-bit systems are impacted by this vulnerability. 

 

 

CVE/Vulnerability

Description

Multiple Code Execution Vulnerabilities in Juniper Junos OS Networking Devices

Monday, 31 October, 2022

Multiple High severity vulnerabilities have been identified in Juniper Networks devices which can be exploited to attain code execution. The J-Web is the main component of the Junos OS which is directly impacted by a remote preauthenticated PHP archive file deserialization vulnerability.

 

These vulnerabilities also could lead to unauthorized local file access, cross-site scripting attacks, path injection and traversal, or local file inclusion .

 

 

Subscribe to RSS FEEDS