-
Design flaws sometimes involve risks, but sometimes they are unknown (CVE-2021-33909)
Preface: A series of sequential read functions for seq operations are defined in fs/seq_file.c. These functions were first introduced in 2001, but have not been used much in the kernel before, and after the 2.6 kernel, many / The seq function is heavily used in proc’s read-only files. Synopsis: Linux kernel 5.13 initially supports Apple’s…
-
A flaw that awakens security vendors – free after use vulnerability (CVE-2021-32589) – 20th July, 2021.
Preface: If you have fgfmsd (TCP/541 / TCP/542) public-facing and have not upgraded to a fixed release, perhaps you should consider the workaround by vendor. Background: The FGFM protocol runs over SSL (Secure Sockets Layer) using TCP port 541 under IPv4. Both FortiGate and FortiManager units have a ‘FGFM’ daemon running exclusively for FortiGate to…
-
Closer look of VMware Thinapp design weakness (CVE-2021-22000) – 18th July 2021
Preface: Secure loading of libraries to prevent DLL preloading attacks, said Microsoft. Background: When an application dynamically loads a dynamic link library (DLL) without specifying a fully qualified path, Windows tries to locate the DLL by searching a well-defined set of directories. If an attacker gains control of one of the directories, they can force…
-
CVE-2021-27610 contained CVSS v3 score of 9.0 and covers an authentication bypass vulnerability in the SAP kernel.(15-7-2021)
Preface: Generally, when it comes to interconnection in the SAP system environment, remote function call (RFC) is one of the main communication protocols used. Observation: About CVE-2021-27610 – SAP resolved the design weakness of the server-side RFC protocol in July 2021. According to the official announcement, a remote attacker can make a special request through…
-
One of the possibilities causes CVE-2021-22928 (14th Jul, 2021)
Preface: (DLL) side-loading is an increasingly popular cyber attack method that takes advantage of how Microsoft Windows applications handle DLL files. Background: Where is the Citrix VDA?By default, the supportability MSI is installed in C:\Program Files (x86)\Citrix\Supportability Tools\ . You can change this location on the Components page of the VDA installer’s graphical interface, or…
-
Staying alert ! Critical ForgeRock Access Management Vulnerability (CVE-2021-35464) 12th JUL 2021
Preface: As a digital identity decision maker in your organization, you already know that in today’s new reality are the cyber security challenges. Centrally manage access permissions to meet best practices in identity management. Product Background: ForgeRock Access Manager/OpenAM supports a wide range of authentication modules (see diagram) that can be configured together using authentication…
-
Is the CVE process late? Esri has managed and remedy those vulnerabilities in May 2021.
Preface: When smartphones and Google Maps were born. The GIS function determines these two functions in a silent manner. Background: Geographic Information System (GIS) plays a key role in military operations. The military uses GIS in various applications, including cartography, intelligence, battlefield management, terrain analysis, remote sensing, etc. – Use of geospatial intelligence:The role of…
-
DarkSide Ransomware ready to move. Operational Technology (OT) should staying alert (7-7-2021)
Preface: IDC report predicted that By 2024, 60% of industrial organizations will integrate data from edge OT systems with cloud-based reporting and analytics, moving from single-asset views to sitewide operational awareness. Background: PowerShell provides an adversary with a convenient interface for enumerating and manipulating a host system after the adversary has gained initial code execution.…
-
CVE-2021-34527 & CVE-2021-1675, no nightmare. Go to sleep well. (7th,JUl 2021)
Preface: Microsoft has assigned CVE-2021-34527 to PrintNightmare. CVE-2021-1675 is similar but distinct from CVE-2021-34527. Background: There is a vulnerability nickname PrintNightmare. PrintNightmare is not the same as CVE-2021-1675, which was fixed in the patch in June. there is currently no patch available for PrintNightmare. Technical Details: The vulnerability numbered CVE-2021-34527 is the same RCE vulnerability…
-
If the design defect cannot be remedied in time. Prevention and detection control is one of them. (Philips Vue PACS) [7-7-2021]
Preface: In theory, if your software application design trusts multiple vendors. Repairing takes more time. Because you need to do more verification. Technology background: Digital Imaging and Communications in Medicine (DICOM) is the standard for the communication and management of medical imaging information and related data. DICOM is most commonly used for storing and transmitting…