Cisco StarOS Software Key-Based SSH Authentication Privilege Escalation Vulnerability

A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could More info: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-staros-ssh-privesc-BmWeJC3h?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20StarOS%20Software%20Key-Based%20SSH%20Authentication%20Privilege%20Escalation%20Vulnerability&vs_k=1

XDR: Identity Matters – Who You Know is As Important as What You Know

Endpoint security is recognizably an essential part of modern cybersecurity, and endpoint security tools are in many cases a first and last line of defense. Endpoint security is focused on securing servers, workloads, end-user workstations, laptops, and any other devices that are used to access corporate networks and SaaS applications. Generally, endpoint security is regarded … ContinuedThe post XDR: Identity Matters – Who You Know is As Important as What You Know appeared first on More info: https://blogs.vmware.com/security/2023/04/xdr-identity-matters-who-you-know-is-as-important-as-what-you-know.html?utm_source=rss&utm_medium=rss&utm_campaign=xdr-identity-matters-who-you-know-is-as-important-as-what-you-know

K000133547 : Python urllib3 vulnerability CVE-2020-26137

Security Advisory Description urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first ... More info: https://my.f5.com/manage/s/article/K000133547?utm_source=f5support&utm_medium=RSS

K000133390 : Apache Tomcat vulnerability CVE-2022-45143

Security Advisory Description The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some ... More info: https://my.f5.com/manage/s/article/K000133390?utm_source=f5support&utm_medium=RSS

SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due More info: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=SNMP%20Remote%20Code%20Execution%20Vulnerabilities%20in%20Cisco%20IOS%20and%20IOS%20XE%20Software&vs_k=1

K000133517 : OpenSSH vulnerability CVE-2023-28531

Security Advisory Description ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. (CVE-2023- ... More info: https://my.f5.com/manage/s/article/K000133517?utm_source=f5support&utm_medium=RSS

K000133511 : QEMU vulnerability CVE-2022-0216

Security Advisory Description A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the ... More info: https://my.f5.com/manage/s/article/K000133511?utm_source=f5support&utm_medium=RSS
Translate »