-
Urgent 11-Tremendous design limitation jeopardizes RTOS industry
Prefect: Headlines new – Critical VxWorks flaws expose millions of devices to hacking. What is VxWorks? The VxWorks RTOS comprises the core capabilities of the wind microkernel(not monolithic) along with advanced networking support, powerful file system and I/O management, and C++ and other standard run-time support. Vulnerability details: The vulnerabilities found on Wind River VxWorks…
-
Mitsubishi electric fr configurator2 – When input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Jul 2019
Preface: Internet of Vehicles (IoV) growth rapidly, meanwhile they are also the potential target of the cyber attacker. About Mitsubishi Electric FR Configurator2: From inverter startup to maintenance, FR Configurator2 allows the user to specify settings easily at the computer. Vulnerability details: CVE-2019-10976 – This vulnerability is triggered when input passed to the XML parser…
-
CVE-2019-4415 IBM Cloud Private privilege escalation Jul 2019
Preface: Refer to market statistic on 2018, the growth in cloud revenues appear to be the strongest for Microsoft and weakest for IBM. Vulnerability details: In IBM Cloud Private on OpenShift icp-scc SecurityContextContraints is erroneously assigned to all pods in all namespaces Remedy: For IBM Cloud Private 3.1.1 or 3.1.2: To resolve the issue, run…
-
CVE-2019-1579 VPN solution impacts Uber, other enterprises may be at risk Jul 2019
Preface: The IoT will make the Taxi Industry change.The business concept of Uber is the industrial leader. Perhaps their concept and ideas are advanced and therefore cyber security are their major concerns. Vulnerability details: Palo Alto Networks PAN-SA-2019-0020 (CVE-2019-1579): Remote Code Execution vulnerability in GlobalProtect Portal/Gateway Interface, especially on SSL Web VPN Applications. Vendor do…
-
CVE-2019-13132 Zeromq libzmq Stack Buffer Overflow Arbitrary Code Execution Vulnerability Jul 2019
Preface: Message queues are unnecessary and cause a lot of overhead (setup such system cab be a lot of work). Product background: Zeromq libzmq A simple synchronous system will just receive a request from the client, perform an operation (anything from retrieving some data from the server to uploading an image) and return a response.…
-
Even though you deployed SSL, stay alert in Python Iot world (CVE-2018-18074)
Preface: The invention of the IoT sensor looks like a contingent driving a smart city. At the same time, the python programming language gives life to the Internet of Things. Security Focus: Even though IoT devices and their back-end facilities deploy SSL certification. It cannot prevent data leakage because of programming language flaw. Vulnerability details:…
-
CVE-2019-13611 python-engineio Origin Header Cross-Site WebSocket Hijacking Vulnerability – Jul 2019
Preface: Smart apps like your friend whenever you need one. Download the app and get a ride from a friendly driver within minutes. Product background: Engine.IO is a lightweight transport protocol that enables real-time bidirectional event-based communication between web browsers and a server. Python-engineio server can form a Eventlet asynchronous server and includes a small…
-
Scientists are busy with scientific development – but should be alert to CVE-2019-12779
Preface: What is the difference of APT group and so called cyber attacker? In normal circumstance, the attack of APT group more often target different political factor of countries or benefits. Background: Physicists and engineers at CERN use the world’s largest and most complex scientific instruments to study the basic constituents of matter. Vulnerability details:…
-
CVE-2019-13272 Linux Kernel (ptrace_link) Unauthorized Access Vulnerability – Jul 2019
Preface: Artificial intelligence especially custom face recognition will be using (ptrace_link). By attaching to another process using the ptrace call, a tool has extensive control over the operation of its target. Vulnerability detail: If a malicious unprivileged child uses PTRACE_TRACEME and the parent is privileged, and at a later point, the parent process becomes attacker-controlled…
-
Fileless Malware Advisory – 17 JUl 2019
Preface: Stolen account information of nearly 750 million users was available for sale on the dark web after hackers breached 24 popular websites. The stolen data, released in two batches, includes names, email addresses and hashed passwords. Description: Spear phishing email with URL to an archive file containing a .lnk file can misleading receiver to…