-
About CVE-2021-43876 Microsoft SharePoint Elevation of Privilege Vulnerability NVD Published – 29-12-2021
Preface: Maybe users who use SharePoint have similar feelings to me. Although SharePoint user permissions are complicated. In addition, the details of the vulnerability also give users a complex feeling! Background: CVE-2021-43976 was published 30th Dec, 2021. However, the vulnerability details has been released by Microsoft on 16th Nov, 2021. Perhaps, official details not described…
-
Apache status updates – 29th Dec 2021
Preface: Traditional, there is service ID account installed in web server side since it require connecting to DB server and update the data into database. Background: Apache log4j vulnerability wide spread in digital world. Additionally, industry area also involved to this design flaw. Enterprise industrial manufacturer Siemens published security advisory that Apache Log4j Vulnerability (CVE-2021-44832)…
-
About CVE-2021-43858 (27th Dec, 2021)
Preface: The main advantage of object storage is that you can group devices into large storage pools, and distribute those pools across multiple locations. Background: Object storage is a technology that manages data as objects. All data is stored in one large repository which may be distributed across multiple physical storage devices, instead of being…
-
About CVE-2021-23175 on NVIDIA GeForce Experience (21-12-2021)
Preface: When the Gamer PC is invaded by an attacker. The inherent risk is not limited to the local PC itself. From a technical point of view, the victim site will be transformed into a weapon to attack other peers. Background: GeForce Experience is the companion application to your GeForce graphics card. It keeps your…
-
Wish you a Merry Christmas and Happy New Year – 2021
-
CVE-2021-39306 – A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10 (22nd Dec, 2021)
Preface: In 2021, there are more than 10 billion active IoT devices.WiFi connection is part of the IoT device.It cannot lack this feature. Background: The Realtek RTL8195AM is a highly integrated single-chip with a low-power-consumption mechanism ideal for IoT (Internet of Things) applications. It combines an ARM®Cortex™-M3 MCU, WLAN MAC, a 1T1R capable WLAN baseband…
-
About Amega: Amega 3.0 will reach its end of life at the end of December 2021. So, it do not plan to release a patch (21st Dec, 2021)
Preface: CVE Numbering Authorities (CNAs) release published vulnerability details for MesaLabs Amega version 3.0 on 12/21/2021. Perhaps the criticality of the design flaw will be impacted whole world including Hospitals, Blood Banks, Pharmaceutical, Laboratories,… As a matter of fact, the related details has been released on HIPAA report on June this year. Background: AmegaView Environmental…
-
When a product encounters a defect, it is not bad news. It will be safer than other products in the future (20th Dec, 2021)
Preface: Sometimes misconfiguration or abuse will be transformed as a vulnerability. Background: Apache Module mod_lua (Official note) -This module holds a great deal of power over httpd, which is both a strength and a potential security risk. It is not recommended that you use this module on a server that is shared with users you…
-
Closer look CVE-2021-22054 – advisory to address a vulnerability in Workspace ONE UEM console (19th Dec 2021)
Preface: CISA urges vigilance on the VMware Workspace ONE UEM console. Background: The aim of configure the httphandler for display blobs (Binary Large Object) such as an image, a video or a file.In a nutshell the blobhandler allows us to get an URL to diplay a blob stored in our database.Whether is there any cyber…
-
About CVE-2021-43812 : Are you using nextjs-auth0 ? (16th Dec, 2021)
Preface: The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Background: The Auth0 Next. js SDK is a library for implementing user authentication in Next[.] js applications. Auth0 offers two ways to implement login authentication for your applications: Universal Login where users log in to your application through a page…