Category: Potential Risk of CVE

  • Cisco Aggregation Services Router 9000 Series IPv6 Fragment Header Denial of Service Vulnerability

    Cisco Aggregation Services Router 9000 Series IPv6 Fragment Header Denial of Service Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180131-ipv6 IPv6 design limitation highlights by Cisco on 2013 RSA conference. Since ICMP header is in 2nd fragment. Defense mechanism especially RA guard no cue where to find (see my cartoon picture). Perhaps stateful firewall can doing the defense. Meanwhile, this issue…

  • CVE-2018-0486 Staying alert with your single sign-on application especially IDP vulnerability

    CVE-2018-0486: Shibboleth(SAML IDP) open source vulnerability is currently awaiting analysis. For more details, see below url for reference: https://nvd.nist.gov/vuln/detail/CVE-2018-0486 During my penetration test engagement in past. I was surprised that no matter airline , financial and retail industries web online application solutions are deployed open source single-sign on resources. An incident occurred in Equifax which…

  • Apple enforce Meltdown and Spectre vulnerabilities remediation

    About Apple security updates announcement (see below url for reference) https://support.apple.com/en-us/HT208463 About security updates announcement, the objectives is going remediate multiple vulnerabilities.As usual, apple released security update but no descriptions are available yet. Perhaps without detail information provided by vendor (Apple). However I  was speculated  that the remediation step will be focus on the following protection…

  • Potential black force – digitize Godzilla

    Preface Can you remember that Science fiction movies Godzilla. The sea monster dubbed Godzilla, his body empowered by nuclear radiation then become huge. However his target is attack the Tokai Nuclear Power Plant and feeding on the nuclear reactor. The Japanese government concluded that nuclear power was what attracted Godzilla. The World in demand of…

  • Potential risk of CVE-2017-15265

    CVE-2017-15265 found on Linux causes privileges escalation. Cisco expert found that it the vulnerability is due to a use-after-free memory error in the ALSA .The ALSA Framework design for audio function. However Android and IoT devices are deployed the ALSA framework on demand. Since Cisco do not have sound on their router, network switch, IDS…