Announcements

Linux Security Updates 02 March 2023

Linux has released security updates to fix vulnerabilities in Linux Kernel and Sudo utility before 1.9.13p2. The addressed vulnerabilities could allow the attacker to execute arbitrary code or cause a denial of service attack on the affected system. Sample of the addressed vulnerabilities: 1. Sudo Code Execution Vulnerability (CVE-2023-27320): • CVSS: 9.8 • Attack Vector: Network • […]

Linux Security Updates 02 March 2023 Read More »

Cisco Security Updates 02 March 2023

Cisco has released security updates to address vulnerabilities affecting multiple products. The severity of the addressed vulnerabilities could allow the remote attacker to gain access, obtain information, cause a denial of service, and trigger Cross-site Scripting (XSS) or server-side request forgery (SSRF) attacks on the affected products. Sample of the addressed vulnerabilities: 1. Cisco IP Phone Command Injection Vulnerability

Cisco Security Updates 02 March 2023 Read More »

Aruba Security Updates 01 March 2023

Aruba has released security updates to fix vulnerabilities across multiple Aruba products. The severity of the addressed vulnerabilities could allow the remote attacker to execute code, obtain information, bypass security restrictions, and perform crosssite scripting. Sample of the addressed vulnerabilities: Unauthenticated Command Injections in the PAPI Protocol (CVE-2023-22747): • CVSS: 9.8 • Attack Vector: Network • Attack Complexity:

Aruba Security Updates 01 March 2023 Read More »

VMware Security Updates 22 February 2023

VMware has released security updates to fix multiple vulnerabilities in multiple VMware products. The addressed vulnerabilities could allow the remote authenticated attacker to read arbitrary files, cause a denial of service attack, conduct an SSRF attack, or execute arbitrary code by using specially-crafted request/XML content to gain access to the affected product. Sample of the addressed vulnerabilities: 1. VMware

VMware Security Updates 22 February 2023 Read More »

Tenable Security Updates 22 February 2023

Tenable has released security updates to fix multiple vulnerabilities in Tenable.sc versions 5.22.0 to 5.23.1 and 6.0.0. The addressed vulnerabilities could allow the remote attacker to cause a denial of service, obtain information, or gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Curl libcurl Denial of Service (CVE-2022-42915): • CVSS: 9.8 • Attack

Tenable Security Updates 22 February 2023 Read More »

Atlassian Security Updates 20 February 2023

Atlassian has released security updates to address vulnerabilities in the “Git” utility that affects multiple products. The addressed vulnerabilities could allow the remote attacker to gain access to the affected systems. Sample of the addressed vulnerabilities: Git Integer Overflow Vulnerability (CVE-2022-41903): • CVSS: 9.8 • Attack Vector: Network • Attack Complexity: Low • Privileges Required: None •

Atlassian Security Updates 20 February 2023 Read More »

Fortinet Security Updates 18 February 2023

Fortinet has released security updates to address multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, bypassing security restrictions, executing arbitrary code, or escalating the privileges on the affected products. Sample of the addressed vulnerabilities: 1. FortiNAC – External Control of File Name or Path in

Fortinet Security Updates 18 February 2023 Read More »

Cisco Security Updates 16 February 2023

Cisco has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform cross-site scripting attacks, bypass security restrictions, execute arbitrary code, or cause a denial of service attack on the affected products. Sample of the addressed vulnerabilities: 1- Cisco ClamAV Buffer Overflow (CVE-2023-20032): • CVSS:

Cisco Security Updates 16 February 2023 Read More »

Intel Security Updates 16 February 2023

Intel has released security updates to fix several vulnerabilities in multiple products. The addressed vulnerabilities could allow the remote attacker to perform various attacks such as obtaining sensitive information, bypassing security restrictions, executing arbitrary code, causing a denial of service, or escalating the privileges on the affected products. Sample of the addressed vulnerabilities: 1- Intel Integrated BMC and OpenBMC

Intel Security Updates 16 February 2023 Read More »

Microsoft February 2023 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch contains a fix for three actively exploited zero-day vulnerabilities. Microsoft has fixed (77) vulnerabilities, with (9) classified as critical as they could allow the attacker to perform code execution, bypass security features, elevate privileges, or cause a denial of service. February’s Patch Tuesday

Microsoft February 2023 Patch Tuesday Read More »

Redhat Security Updates 12 February 2023

Redhat has released security updates to address multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to perform various attacks such as denial of service attacks, execute arbitrary code, or escalate privileges on the affected system. Sample of the addressed vulnerabilities: 1. Apache MINA SSHD Code Execution (CVE-2022-45047): • CVSS: 9.8 • Attack Vector:

Redhat Security Updates 12 February 2023 Read More »

Atlassian Security Updates 02 February 2023

Atlassian has released a security update to fix a critical vulnerability in multiple versions of the Jira Service Management Server and Data Center. The mentioned vulnerability could allow the attacker to impersonate another user and gain access to the Jira Service Management instance under certain circumstances: • Write access to the User Directory is enabled. • Outgoing email

Atlassian Security Updates 02 February 2023 Read More »

Tenable Security Update 01 February 2023

Tenable has released a security update to fix a critical vulnerability in multiple products. The mentioned vulnerability could allow the authenticated remote attacker to escalate privileges by modifying environment variables and abusing the impacted plugin on the affected system. Tenable.io, Tenable.sc, and Nessus Privilege Escalation (CVE-2023-0524): CVSS: 9.1 Attack Vector: Network Attack Complexity: Low Privileges Required: High User

Tenable Security Update 01 February 2023 Read More »

QNAP Security Update 31 January 2023

QNAP has released a security update to address a critical vulnerability across QNAP QTS and QNAP QuTS hero. The severity of the addressed vulnerability could allow the remote unauthenticated attacker to inject and execute malicious code on the affected systems by sending specially crafted requests. QNAP running QTS and running QTS code execution (CVE-2022-27596): CVSS: 9.8 Attack Vector:

QNAP Security Update 31 January 2023 Read More »

VMware Security Updates 25 January 2023

VMware has released security updates to fix multiple vulnerabilities in VMware vRealize Log Insight. The severity of the addressed vulnerabilities could allow the remote attacker to gain access, cause a denial of service attack, or obtain information from the affected systems. Sample of the addressed vulnerabilities: 1. VMware vRealize Log Insight Broken Access Control Vulnerability (CVE-2022-31704): • CVSS:

VMware Security Updates 25 January 2023 Read More »

Tenable Nessus Security Updates 22 January 2023

Tenable Nessus has released updated versions (Nessus 10.4.2, 8.15.8) to fix a privilege escalation vulnerability. The mentioned vulnerability could allow the authenticated attacker to execute a specially crafted file to obtain root or NT AUTHORITY/SYSTEM privileges on the affected Nessus host. Tenable Nessus Privilege Escalation Vulnerability (CVE-2023-0101): • CVSS: 9.1 • Attack Vector: Network • Attack Complexity: Low

Tenable Nessus Security Updates 22 January 2023 Read More »

Oracle Security Patch Updates January 2023

Oracle released its critical patch updates for January 2023, containing (327) new security patches for multiple affected products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. This critical patch update provides security updates to fix several vulnerabilities that may be remotely exploitable without authentication in a wide range of product families,

Oracle Security Patch Updates January 2023 Read More »

ManageEngine Security Update 17 January 2023

ManageEngine has released a security update to address a critical vulnerability affecting multiple products. The severity of the addressed vulnerability could allow the remote attacker to execute arbitrary code on the system by sending a specially-crafted request. It should be highlighted that the admins of ManageEngine were warned about a proof-of-concept (POC) that has been created to exploit

ManageEngine Security Update 17 January 2023 Read More »

Cisco Security Updates 12 January 2023

Cisco has released security updates to address several vulnerabilities in multiple Cisco products. The released security updates fix several vulnerabilities affecting multiple Cisco products such as RV016, RV042, RV042G, and RV082 Routers, IP Phone 7800 and 8800 Series, Industrial Network Director (IND), and Cisco Webex Room Phone. The addressed vulnerabilities could allow the attacker to send a specially

Cisco Security Updates 12 January 2023 Read More »

Microsoft January 2023 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch contains a fix for an actively exploited zero-day vulnerability. Microsoft has fixed (98) vulnerabilities, with (11) classified as critical as they allow remote code execution, bypass security features, or elevation of privileges. January’s Patch Tuesday was released to fix security flaws in

Microsoft January 2023 Patch Tuesday Read More »