-
Schneider Electric Security Notification – CVE-2019-6811 (Sep 2019)
Product background: The Modicon Quantum Ethernet I/O (QEIO) automation platform is designed to meet the requirements of both the industrial automation and process industries. Vulnerability details: An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists, which could cause denial of service when the module receives an IP fragmented packet with a length greater…
-
Dejablue vulnerability – Impact on Siemens Health Products (10th Sep 2019)
For healthcare, cyber attacks can have ramifications beyond financial loss and breach of privacy. Preface: For healthcare, cyber attacks can have ramifications beyond financial loss and breach of privacy. Background: The DejaBlue vulnerabilities are in the early stages of the RDP connection. The flaws precede the authentication phase, thereby there is no need for passwords…
-
CVE-2019-15292 Linux Kernel up to 5.0.8 atalk_proc.c atalk_proc_exit memory corruption
Background: Appletalk support allows your Linux machine to interwork with Apple networks. Below components conduct the specified functions. sysctl_net_atalk.c: sysctl interface to net AppleTalk subsystem. ddp.c: AppleTalk DDP protocol for Ethernet ELAP (ethertalk). atalk_proc.c: proc support for Appletalk The Use-After-Free vulnerability is related to above three components. Even though you do not use ApplyTalk, attacker…
-
Quick and Dirty – walk through CVE-2019-15846
Preface: Quite a lot of cyber security expertise provides their explanation on vulnerability on Exim (A local or remote attacker can execute programs with root privileges). I will do a quick and dirty way to explain. Should you have interested, please refer below: a. Connect to Exim with TLS and send an SNI that ends…
-
CIS Center for Internet Security Urge PHP customer aware of Multiple Vulnerabilities in PHP. Because it could allow for Arbitrary Code Execution. Sep 2019
Preface: Network security experts may hesitate to answer a question. What is it? Which programming language is easy to write. But there are no loopholes. CIS Center for Internet security announcement: Multiple Vulnerabilities in PHP Could Allow for Arbitrary Code Execution For more information, please refer URL – https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2019-087/ Our Observation: One of the component…
-
The Unforgettable computer architecture – I do not mind it has vulnerability occur. Sep 2019
Preface: Quite a number of people think that Mainframe computer no longer exist anymore. However they are still alive. Background: A 3270 Emulator is a terminal emulator that duplicates the functions of an IBM 3270 mainframe computer terminal on a PC or similar microcomputer. Vulnerability details: There is Missing SSL Certificate Validation in the pw3270…
-
Reflections on the Connection Between SSH client and SSH service Daemon – CVE-2019-1580 (PAN-OS – Palo Alto Networks)
Preface: No matter “WAF” or a traditional Layer 3 firewall. The SSH service daemon will be installed because such service is not uncommon. Vulnerability details: Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message…
-
YouPHPTube 7.4 – Remote Code Execution Sep 2019
Preface: As time goes by, youth not familiar with TV at home. Obviously the online video is the new generation of choice. Product background: With YouPHPTube you can create your own video sharing site, YouPHPTube will help you import and encode videos from other sites like Youtube, Vimeo, etc. and you can share directly on…
-
CVE-2019-15753 OpenStack (os-vif 1.15.x before 1.15.2, and 1.16.0), allows users to possibly view the content of packets for instances belonging to other tenants sharing the same network. Aug 2019
Preface: Virtual computer world like a fruit punch, anything can mix into it. Background: OpenStack is a cloud computing software developed by NASA and Rackspace. It is licensed under the Apache license and is a free and open source software. Their customer including Shanghai Electric, China Mobile, LINE and China UnionPay . Vulnerability details: In…
-
CVE-2019-12643 Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability (Aug 2019)
Preface: Because a stateless API can increase request overhead by handling large loads of incoming and outbound calls, a REST API should be designed to encourage the storage of cacheable data. Vulnerability details: A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to…