-
Buffer overflow is difficult to avoid, it can easily happen!
Preface: There are two primary types of buffer overflow vulnerabilities: Stack overflow and Heap overflow. Product background: The administrative command–line client is a program that runs on a file server, workstation, or mainframe. It is installed as part of the Tivoli Storage Manager server installation process. The administrative client can be accessed remotely. From the…
-
CVE-2020-3985 VMWARE SD-WAN Orchestrator vulnerability (19th Nov 2020)
Preface: Most SD-WAN suppliers have partnerships with leading cloud platforms, and they use a variety of methods to accelerate traffic coming to and from cloud platforms. But IT pros say, it should look for better security. Background: The Orchestrator provides you with a JSON-RPC API, which means you call it over HTTPS. It’s not a…
-
CVE-2020-16846 – SaltStack Salt(6th Nov 2020)
Preface: The interconnect component of the opensource application is the opensource software. Background: Salt (sometimes referred to as SaltStack) is Python-based, open-source software for event-driven IT automation, remote task execution, and configuration management. Vulnerability details: An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH…
-
What is the impact of CVE-2020-26892? (17-11-2020)
NATS Srv wiki – Cloud native messaging system made for developers and operators who want to spend more time doing their work and lesstime worrying about how to do messaging. End user of this product: Mastercard, Baidu, Alibaba Group, VMware, GE, Pivotal, Telia Company, netlify, htc, GE, Zephyr Project, tinder and ERICSSON Vulnerability details: Some…
-
Replay Protected Memory Block (RPMB) protocol vulnerability impact may more than expected – 16th Nov 2020.
Preface: With the advent of the 5G era, starting in 2019, UFS 3.0 has gradually been adopted by flagship smartphones.UFS 3.1 is an optimized version of 3.0. Background: The RPMB layer aims to provide in-kernel API for Trusted Execution Environment (TEE) devices that are capable to securely compute block frame signature. In case a TEE…
-
Security focus – Multiple vulnerability on SAP solution manager – 11th Nov 2020
Preface: CMDB is a repository that should contain only business critical items that you want to track. It should contain a record of information that allows you to answer business critical questions and helps you to connect business processes. CMDB should contain all the items that are important for your business or a service. About…
-
Cisco product security alert (CVE-2020-26070). It may awaken other manufacturers require to focus on similar matters. (11th Nov 2020)
Preface: Our daily life is relies on Cloud computing system. Smart City, GPRS, mapping & spatial analytics technology their backend system are located on cloud. Apart of cloud system operation and architecture. The inter network empower its life. Background: In our digital world , networks packet processing functions are dynamically injected into the network. Each…
-
CVE-2020-27977 – Vendor not explicitly explain the vulnerability details, but most likely is fall into this scenario (9th Nov 2020)
Preface: Have you heard a terms, so called take Ownership of his Registry key? Background: CapaSystems helps businesses achieve greater efficiency through Device Management and Monitoring by using CapaInstaller and PerformanceGuard. The purpose for the CapaInstaller Agent Health Check is to maintain a healthy and up to date agent on every computer/server. Vulnerability details: A…
-
Shibboleth vulnerability cve-2020-27978 – 28th Oct 2020
Preface: This vulnerability disclosed one year ago. Perhaps the details of defect you require to know. Background: Shibboleth is a web-based Single Sign-On infrastructure. It is based on SAML. Shibboleth does not carry out authentication itself. SAML (Security Assertion Mark-up Language) is an umbrella standard that covers federation, identity management and single sign-on (SSO). Vulnerability…
-
Design limitation of iDS6 DSSPro Digital Signage System 6.2 – 6th Nov 2020
Preface: Digital signage’s content is powered by a media player or system-on-a-chip which pushes content to a display.Users can then manage the content with a content management system. Background: Design limitation of iDS6 DSSPro Digital Signage System 6.2 . The vulnerability cause by autoSave password function.Since it is a pure unencrypted http traffic, it let…