Author: admin

  • CVE-2022-27950 – Design weakness in drivers/hid/hid-elo.c (impacted to ELO Touchscreen Monitor product) – 28th Mar 2022

    Preface: Touchscreens provide direct navigation and accessibility through physical touch controls, eliminating the need for traditional computer mice and keyboards. Background: Touchscreens are common in devices such as game consoles, personal computers, electronic voting machines, and point-of-sale (POS) systems. Elo’s IntelliTouch controllers are designed and manufactured to work specifically with IntelliTouch SAW touchscreens for optimal…

  • About CVE-2022-27948 (Tesla electric cars) – 27th Mar 2022

    Preface: Hacking using RF tools due to RF transmit power limiting capabilities. From a technical point of view, it is similar to a short-range attack. Compared to traditional network attacks that run on top of TCP/IP networks. Network-based cyberattacks will be more disruptive because they are not limited to a single device. Background: The following…

  • CVE-2022-21820 – NVIDIA DCGM contains a vulnerability in nv-hostengine (24th Mar, 2022).

    Preface:The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. Background: The NVIDIA host engine, nv-hostengine, is a thin wrapper around the DCGM shared library. Its main job is to instantiate the DCGM library as a…

  • CVE-2022-27666 – a buffer overflow in ESP transformation in net/ipv4/esp4.c and net/ipv6/esp6.c via a large message. (23rd Mar 2022)

    Preface: There are two types of buffer overflows: stack-based and heap-based. Heap-based, which are difficult to execute and the least common of the two, attack an application by flooding the memory space reserved for a program. Background: Encapsulating Security Payload (ESP) is a protocol in the Internet Protocol Security (IPsec) family that encrypts and authenticates…

  • About BIND 9.18.0 (22nd Mar, 2022)

    Preface: The registration of CVE records is largely out of sync with the time of the event. Perhaps the new release of CVE record by today, however it was happened few weeks or months ago. But with reference of these vulnerabilities records. Vulnerability scanner can precisely provide a result to you after scan. Background: BIND…

  • About CVE-2022-24237 (21st Mar 2022)

    Preface: What is application layer load balancing?Application layer load balancers distribute requests based on content of the requests being processed, including its HTTP/S header and message in addition to session cookies. They can also track responses as they travel back from the server, thereby providing data on the load each server is processing at all…

  • About CVE-2022-27250 (18th Mar, 2022)

    Preface: Firmware is stored in a flash memory either inside or outside of a microcontroller. If Firmware had vulnerability occurs. It should finally do the Firmware update to fix the problem.Firmware is usually found in general purpose computing devices like smartphones, PCs, laptops, etc. Background: About CVE-2022-27250, may be this matter occured since 2019. The…

  • CVE-2022-0237 – Certain versions of Insight Agent from Rapid7 contain a privilege escalation vulnerability. (17th Mar 2022)

    Preface: A lot of people will familiar with Rapid 7 (metasploit), it is a powerful penetration test tools in existing market. If the product only provide a penetration test tool in today demanding market. It is limited the business development. However, from my personal point of view, SIEM and log management functions by Rapid 7…

  • CVE-2022-27223 Linux UDC driver design weakness (16th Mar 2022)

    Preface: The registration of CVE records is largely out of sync with the time of the event. Perhaps the new release of CVE record by today, however it was happened few weeks or months ago. But with reference of these vulnerabilities records. Vulnerability scanner can precisely provide a result to you after scan. Background: A USB…

  • About CVE-2022-27005 (15th Mar 2022)

    Preface: The registration of CVE records is largely out of sync with the time of the event. Perhaps the new release of CVE record by today, however it was happened few weeks or months ago. But with reference of these vulnerabilities records. Vulnerability scanner can precisely provide a result to you after scan. Background: About…