-
Advantech WebAccess/SCADA Multiple Security Vulnerabilities – Jan 2019
Preface: Advantech is a leading brand in IoT intelligent systems, Industry 4.0, machine automation, embedding computing, embedded systems, transportation, … New vulnerabilities found in WebAccess/SCADA Version 8.3: CVE-2019-6519 – An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker to upload malicious data. CVE-2019-6521 – Specially crafted requests could allow…
-
UK-based Metro Bank has suffered an SS7 attack – Jan 2019
Preface: The phrase “old wine in new bottles”! Cyber security world has similar things all the time! About SS7 design weakness: Business impact: A U.K. bank says no customers lost money after cyber attackers attempted account takeovers by rerouting one-time passcodes, Motherboard reports. The National Cyber Security Centre (NCSC) also confirmed. Such attacks involve tampering…
-
Docker (runc) – Malicious container escape – CVE-2019-5736 (11th Feb 2019)
Preface: runc is a CLI tool for spawning and running containers according to the OCI specification. Vulnerability: Found vulnerability on runc affecting several open-source container management systems that leverage runc Impact: The vulnerability allows a malicious container to overwrite the host runc binary and thus gain root-level code execution on the host. But exploit this…
-
Understand New implemented China Cyber Law – 2019
Aim to security: The new regulations on China’s Cybersecurity Law on November 2018 grant China cyber security agencies (the legal authority) to conduct remote testing of any Internet-related business operating in China. Their authority is possible to copy and share any data that government officials find on the system being inspected. MPS (The Ministry of…
-
Cisco finally fixed Elastic Services Controller Service 3.0 Portal Authentication Bypass Vulnerability (CVE-2018-0121) – 8th Feb 2019
Preface: It was because of new version 4.0 introduced on Jan 2018. Cisco urge customers upgrade to 4.0 to do the remediation. The Elastic Services Controller Service Portal Authentication Bypass Vulnerability finally fixed on Feb 2019. Product background: Cisco ESC provides a single point of control to manage all aspects of VNF lifecycle for generic…
-
CVE-2019-6978 – GD Graphics Library gdImage*Ptr() Functions Double Free Vulnerability – Feb 2019
-
Apple Releases Multiple Security Updates – 7th Feb 2019
Preface: Apple found memory vulnerability, since no additional information will be provided by vendor. Does it relate to DUI (Dereference Under the Influence)? What is DUI?Attackers use the DUI vulnerability as a memory access service to mount attacks. Their aim to influence memory operations of isolated components through inputs to their public interface. Apple Releases…
-
The PAN-OS management web interface Vulnerability (CVE-2019-1566) – Jan 2019
Preface: Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. Background: A WAF is deployed to protect a specific web application or set of web applications. Generally, the common attacks such as cross-site scripting (XSS)…
-
Marvell Avastar wireless SoCs have multiple vulnerabilities – 5th Feb 2019
Preface: The Marvell 88W8897A SoC (System on a Chip) is the industry’s first 802.11ac chip to combine Bluetooth 4.2, mobile MIMO (Multi-input Multi-output), transmit beamforming, and with built-in support for all screen projection technologies. Technology Background: Computer design primary focus on memory usage. Even though without an exception in SoC (System on a Chip) design.…
-
Avahi avahi-daemon vulnerability (CVE-2017-6519) remedy has finally been released!
Preface: Avahi is a free zero-configuration networking (zeroconf) implementation, including a system for multicast DNS/DNS-SD service discovery. Technical background: Multicast DNS (mDNS) is a protocol that uses packets similar to unicast DNS except sent over a multicast link to resolve hostnames. Vulnerability found in Avahi: The vulnerability exists because the affected software misses link-local checks,…