Showing posts with label vulnerability. Show all posts
Showing posts with label vulnerability. Show all posts

Severity Rating: HIGH

Software Affected
·         IBM WebSphere Application Server versions 7.0, 8.0, 8.5, 9.0
·         IBM WebSphere Application Server ND versions 8.5, 9.0
·         IBM WebSphere Virtual Enterprise versions 7.0, 8.0

Overview
Multiple vulnerabilities have been reported in IBM WebSphere Application
Server which could allow a remote attacker to execute arbitrary code or
obtain sensitive information.

Description
1.     Remote Code Execution Vulnerability (CVE-2020-4448)
This vulnerability exists in the BroadcastMessageManager class of IBM
WebSphere Application Server Network Deployment due to improper validation
of user-supplied input. A remote attacker could exploit this vulnerability
by executing a specially-crafted sequence of serialized objects from
untrusted sources.

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the target system.

2.     Remote Code Execution Vulnerability (CVE-2020-4450)
This vulnerability exists in the IIOP protocol of IBM WebSphere Application
Server due to improper validation of user-supplied input. A remote attacker
could exploit this vulnerability by executing a specially-crafted sequence
of serialized objects.

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the target system.

3.     Information Disclosure Vulnerability (CVE-2020-4449)
This vulnerability exists in the IIOP protocol of IBM WebSphere Application
Server due to improper validation of user-supplied input. A remote attacker
could exploit this vulnerability by executing a specially-crafted sequence
of serialized objects.
Successful exploitation of this vulnerability could allow the attacker to
disclose sensitive information of the target system.

Solution
Contact device vendor or manufacturer for appropriate over-the-air update

Vendor Information
IBM

References
IBM

ZDI

CVE Name
CVE-2020-4448
CVE-2020-4449
CVE-2020-4450

Severity Rating: High

Systems Affected
·         WordPress versions 5.4.1 and prior

Overview
Multiple vulnerabilities have been reported in WordPress that could allow a
remote attacker to perform cross-site scripting attack, gaining elevated
privileges or sensitive information disclosure on the targeted system.

Description
These vulnerabilities exist due to insufficient sanitization of
user-supplied data, and improper impose of security restrictions. A remote
attacker could exploit these vulnerabilities by executing arbitrary script
code in user's browser.

Successful exploitation of these vulnerabilities could allow the attacker
to perform cross-site scripting attack, gaining elevated privileges or
access to sensitive information on the targeted system.

Solution
Upgrade to WordPress version 5.4.2
- -release/

Vendor Information
WordPress

- -release/

References
WordPress
- -release/
Wordfence
- -vulnerabilities/
US-CERT
- -security-and-maintenance-update

Severity rating: High

Software affected
·        Microsoft SharePoint Enterprise Server 2016
·        Microsoft SharePoint Foundation 2010 Service Pack 2
·        Microsoft SharePoint Foundation 2013 Service Pack 1
·        Microsoft SharePoint Server 2019

Overview
A vulnerability has been reported in Microsoft SharePoint Server which
could allow a remote attacker to execute arbitrary code on the targeted
system.

Description
1.  Remote Code Execution Vulnerability (CVE-2020-1181)

This vulnerability exists in Microsoft SharePoint Server due to improper
identification and filtration of unsafe ASP.Net web controls. A remote
attacker could exploit this vulnerability by using a specially crafted page
on the affected server.

Successful exploitation of this vulnerability could allow the attacker to
cause remote code execution on the targeted system.

Solution
Apply appropriate patches as mentioned in Microsoft Security Guidance

Vendor Information
Microsoft
- -1181

References
Microsoft
- -1181

CVE Name
CVE-2020-1181

Severity Rating: HIGH
Software Affected
Open Enclave SDK
Overview

A vulnerability has been reported in Open Enclave SDK which could allow
remote attacker to improperly handle objects on the targeted system.
Description

An information disclosure vulnerability exists in Open Enclave SDK due to
improper handling of objects in memory. An attacker could exploit this
vulnerability by compromising the host application running the enclave
without user interaction. 

Successful exploitation of this vulnerability could allow an attacker to
obtain information stored in the Enclave.

Solution

Apply appropriate patches as mentioned in following vendor advisory: 
- -1369

Vendor Information
Microsoft
- -1369

References

Microsoft
- -1369

CVE Name
CVE-2019-1369
Severity Rating: HIGH

Software Affected
Linux kernel through 5.3.6
Overview
Vulnerability has been reported in Linux which could allow an attacker to
access sensitive information on a targeted system.

Description

This vulnerability exists due to Realtek Wi-Fi chips model in Linux
devices. An attacker could exploit this vulnerability by rtlwifi driver
that mainly supports the Realtek Wi-Fi chips model used in Linux devices.

Successful exploitation of this vulnerability could allow an attacker to
compromise a system using nearby Wi-Fi devices.

Solution
Apply appropriate updates as mentioned in the following URL:
https://lkml.org/lkml/2019/10/16/1226
Vendor Information

Linux
https://lkml.org/lkml/2019/10/16/1226

References

Linux
https://lkml.org/lkml/2019/10/16/1226
https://arstechnica.com/information-technology/2019/10/unpatched-linux-flaw
- -may-let-attackers-crash-or-compromise-nearby-devices/

CVE Name
CVE-2019-17666

Software Affected 
•SAP Application Server ABAP, Versions -  2008_1_46C, 2008_1_620,
2008_1_640, 2008_1_700, 2008_1_710, 740
•SAP Business Client, Version - 6.5
•SAP Business Objects Business Intelligence Platform (Live Data
Connect), Versions - 1.0, 2.0, 2.x
•SAP Adaptive Server Enterprise (Backup Server), Version -  16.0
•SAP Business Objects Business Intelligence Platform (CrystalReports
WebForm Viewer), Versions - 4.1, 4.2
•SAP Adaptive Server Enterprise (Cockpit), Version - 16.0
•SAP Adaptive Server Enterprise (XP Server on Windows Platform),
Versions - 15.7, 16.0
•SAP Master Data Governance, Versions - S4CORE 101; S4FND 102, 103, 104;
SAP_BS_FND 748
•SAP Adaptive Server Enterprise (Web Services), Versions - 15.7, 16.0 
•SAP Business Client, Version - 7.0
•SAP Business Objects Business Intelligence Platform, Version - 4.2
•SAP Adaptive Server Enterprise, Versions - 15.7, 16.0
•SAP Enterprise Threat Detection, Versions - 1.0, 2.0
•SAP Master Data Governance, Versions - 748, 749, 750, 751, 752, 800,
801, 802, 803, 804 
•SAP Business Objects Business Intelligence Platform (CMC and BI
launchpad), Version - 4.2
•SAP Plant Connectivity, Versions - 15.1, 15.2, 15.3, 15.4
•SAP NetWeaver AS ABAP (Web Dynpro ABAP), Version - SAP_UI 750, 752,
753, 754; SAP_BASIS 700, 710, 730, 731, 804
•SAP Business Objects Business Intelligence Platform, Versions - before
4.1, 4.2 and 4.3
•SAP Identity Management, Version - 8.0

Overview 
Multiple vulnerabilities have been reported in SAP products, which could be
exploited by a remote attacker to execute arbitrary code, inject malicious
code, obtain sensitive information, cause denial of service conditions,
perform cross-site scripting attacks, leading to path traversal or perform
other unauthorized activities on a targeted system. 

Description
These vulnerabilities exist in SAP products due to incorrect hardening of
the XML Parser,insufficient encoding of user-controlled inputs,unsafe
deserialization error,insufficient validation of path information provided
by users, use-after-free errors, improper parsing of RPT files, improper
input validations and other flaws in the affected software. 

A remote attacker could exploit these vulnerabilities by injecting
malicious code, performing unauthorized queries, sending a specially
crafted XML file & GIOP packets,  which could allow the attacker to
overwrite, delete, or corrupt files on a targeted system. 

Successful exploitation of these vulnerabilities could allow the attacker
to inject malicious code, execute arbitrary code, obtain sensitive
information, cause denial of service conditions, perform cross-site
scripting attacks or perform other unauthorized activities on a targeted
system.

Solution 
Apply appropriate patches as mentioned on SAP website:   
Vendor Information

SAP

References
SAP
Onapsis
CVE Name
CVE-2020-6253
CVE-2020-6262
CVE-2020-6242
CVE-2020-6248
CVE-2020-6219
CVE-2020-6252
CVE-2020-6241
CVE-2020-6243
CVE-2020-6249
CVE-2020-6244
CVE-2020-6250
CVE-2020-6245
CVE-2020-6247
CVE-2020-6251
CVE-2020-6259
CVE-2020-6254
CVE-2020-6256
CVE-2020-6257
CVE-2020-6240
CVE-2019-0352
CVE-2020-6258

Severity Rating: HIGH
Software Affected 
•ISC BIND versions 9.0.0 to 9.11.18
•ISC BIND versions 9.12.0 to 9.12.4-P2
•ISC BIND versions9.13.x
•ISC BIND versions9.14.0 to 9.14.11
•ISC BIND versions9.15.x
•ISC BIND versions9.16.0 to 9.16.2
•ISC BIND versions 9.17.0 to 9.17.1 
•ISC BIND versions 9.9.3-S1 to 9.11.18-S1

Overview 
Multiple vulnerabilities have been reported in ISC BIND which could allow a
remote attacker to cause denial of service conditions on a targeted system.

Description
1.  Denial of Service Vulnerability ( CVE-2020-8617   ) 

This vulnerability exists in BIND due to a logic error in tsig.c. A remote
attacker could exploit this vulnerability by sending a specially crafted
message to the affected server.
Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions on the targeted system. 

2. Denial of Service (Performance degradation)Vulnerability ( CVE-2020-8616
  ) 

This vulnerability exists in BIND due to insufficient limiting of the
number of fetches performed when processing referrals. A remote attacker
could exploit this vulnerability by using specially crafted referrals.
Successful exploitation of this vulnerability could allow the attacker to
cause denial of service (performance degradation) conditions on the
targeted system. The attacker may also exploit this vulnerability to use
the recursing server as a reflector in a reflection attack with a high
amplification factor. 

Solution
Update to the latest versions as available at the following URL: 

Vendor Information
ISC

References
Debian
IBM X-Force Exchange
Severity Rating: HIGH
Component Affected 
•MDS 9100 Series Multilayer Fabric Switches
•MDS 9250i Multiservice Fabric Switches
•MDS 9300 Series Multilayer Fabric Switches.

Overview 
Vulnerability has been reported in the resource handling system of Cisco
NX-OS Software for Cisco MDS 9000 Series Multilayer Switches which could
allow an unauthenticated, remote attacker to cause a denial of service
(DoS) condition on an affected device. 
Description
A Vulnerability exists in the resource handling system of Cisco NX-OS
Software for Cisco MDS 9000 Series Multilayer Switches  due to improper
resource usage control that could allow the attacker to cause a denial of
service (DoS) condition. An attacker could exploit this vulnerability by
sending traffic to the management interface (mgmt0) of an affected device
at very high rates and this  could allow the attacker to cause unexpected
behaviors such as high CPU usage, process crashes, or even full system
reboots of an affected device. 

Successful exploitation of this vulnerability could allow the attacker to
cause a denial of service (DoS) condition. 

Solution
Apply appropriate updates as mentioned in: 
- -sa-20200226-mds-ovrld-dos

Vendor Information
CISCO
- -sa-20200226-mds-ovrld-dos

References
CISCO
- -sa-20200226-mds-ovrld-dos
CVE Name
CVE-2020-3175
Severity Rating: High 
Software Affected 
•BIND 9.16.x versions from 9.16.0 to 9.16.2
•BIND 9.14.x versions from 9.14.0 to 9.14.11
•BIND 9.11.x versions from 9.11.0 to 9.11.18
•BIND Supported Preview Edition from 9.9.3-S1 to 9.11.18-S1
•BIND 9 versions prior to 9.10.x, 9.12.x, 9.13.x and 9.15.x
(non-supported), and development branch versions 9.17.x
•NLnet Labs Unbound up to 1.10.0
•NIC.CZ Knot Resolver before 5.1.1
•PowerDNSRecursor from 4.1.0 through 4.3.0 

Other products implementing the vulnerable DNS protocol may also be
affected.

Overview 
A vulnerability has been reported in the DNS protocol, which could be
exploited by a remote attacker to amplify network traffic (1620x) by
sending DNS queries to a vulnerable resolver, which queries an
authoritative server controller by the attacker (NXNSAttack). 

Description
This vulnerability abuses DNS delegation mechanism to force DNS resolvers
to generate more DNS queries to authoritative servers controlled by
attacker. This attack, known as NoneXistentNameServers Attack (NXNSAttack),
can result in an amplification factor of over 1620. The attack also
saturates the ¿NS¿ resolver caches. 

The attacker sends such a request multiple times over a long period of
time, which generates huge quantity of requests between the DNS servers,
which are subsequently overwhelmed and unable to respond to the legitimate
requests of actual legitimate users.

Solution 
•Apply appropriate patches/updates as recommended by respective vendors.

Vendor Information
PowerDNS
20-01.html
ISC BIND
NLnet Labs 
Knot Resolver
Microsoft 
9

References

kind-of-random-subdomain-attack/
20-01.html

CVE Name
CVE-2020-8616
CVE-2020-10995
CVE-2020-12662
CVE-2020-12663
CVE-2020-12667
Severity Rating: HIGH
Software Affected 
•Cisco ASA Software or FTD Software.

Overview 
Vulnerability has been reported in the web services interface of Cisco
Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat
Defense (FTD) Software which could allow an unauthenticated, remote
attacker to conduct directory traversal attacks and obtain read and delete
access to sensitive files on a targeted system. 

Description
A Vulnerability exists inthe web services interface of Cisco Adaptive
Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)
Software due to a lack of proper input validation of the HTTP URL that
could allow the attacker to access sensitive files on a targeted system. An
attacker could exploit this vulnerability by sending a crafted HTTP request
containing directory traversal character sequences and allow the attacker
to view or delete arbitrary files on the targeted system. The file system
is enabled when the affected device is configured with either WebVPN or
AnyConnect features. When the device is reloaded after exploitation of this
vulnerability, any files that were deleted are restored. 

Successful exploitation of this vulnerability could allow the attacker to 
obtain read and delete access to sensitive files on a targeted system. 

Solution
Apply appropriate updates as mentioned in: 
- -sa-asaftd-path-JE3azWw43

Vendor Information
CISCO
- -sa-asaftd-path-JE3azWw43

References
CISCO
- -sa-asaftd-path-JE3azWw43

CVE Name
CVE-2020-3187
Severity Rating: HIGH
Software Affected 
•Windows installer for PostgreSQL versions12.3, 11.8, 10.13, 9.6.18, and
9.5.22
Overview 
A vulnerability has been reported in PostgreSQL which could be exploited by
an attacker to execute arbitrary code on a targeted system. 

Description
This vulnerability exists in PostgreSQL installer for Windows due to
failure to use fully-qualified paths for invoking system-provided
executables. An attacker could exploit this vulnerability by tricking a
user to install PostgreSQL from a directory that contains malicious files. 

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code with the privileges of the PostgreSQL installer on
the targeted system.
Note: - This vulnerability affects Windows installer only. 

Solution
Apply appropriate updates as mentioned in: 

Vendor Information
PostgreSQL.org

References
PostgreSQL.org
CybersecurityHelp
Vulmon

CVE Name
CVE-2020-10733
Severity Rating: HIGH
Software Affected 
•Cisco ASA Software or FTD Software.
Overview 
Vulnerability has been reported in the web services interface of Cisco
Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat
Defense (FTD) Software which could allow an unauthenticated, remote
attacker to retrieve memory contents on an affected device, which could
lead to the disclosure of confidential information. 

Description
A Vulnerability exists in the web services interface of Cisco Adaptive
Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)
Software due to a buffer tracking issue when the software parses invalid
URLs that are requested from the web services interface that could allow
the attacker to disclose the confidential information. An attacker could
exploit this vulnerability by sending a crafted  GET request to the web
services interface. 

Successful exploitation of this vulnerability could allow the attacker to
retrieve memory contents, which could lead to the disclosure of
confidential information. 

Solution
Apply appropriate updates as mentioned in: 
- -sa-asaftd-info-disclose-9eJtycMB

Vendor Information
CISCO
- -sa-asaftd-info-disclose-9eJtycMB

References
CISCO
- -sa-asaftd-info-disclose-9eJtycMB

CVE Name
CVE-2020-3259
Severity Rating: HIGH
Software Affected 
•Honor View20, Versions earlier than 10.0.0.179(C636E3R4P3)
•Honor View20, Versions earlier than 10.0.0.180(C185E3R3P3)
•Honor View20, Versions earlier than 10.0.0.180(C432E10R3P4)
•Honor View20, Versions earlier than 10.0.0.188(C00E62R2P11)
•Honor 20, Versions earlier than 10.0.0.187(C00E60R4P11)
•Honor 20 PRO, Versions earlier than 10.0.0.187(C00E60R4P11)
•Honor Magic2, Versions earlier than 10.0.0.176(C00E60R2P11)
•Honor P20, Versions earlier than 10.0.0.156(C00E156R1P4)

Overview 
Multiple vulnerabilities have been reported in Huawei Smartphones which
could allow an attacker to access sensitive information and bypass
authentication on the targeted system. 

Description
1. Out of Bound Read Vulnerability ( CVE-2020-1808   ) 

An Out of Bound Read Vulnerability exists in some Huawei Smartphones. This
vulnerability exists because the software reads data past the intended
buffer. due to installing a crafted application. A remote attacker could
exploit this vulnerability by tricking the user into installing a crafted
application on the targeted system.
Successful exploitation of this vulnerability could allow the remote
attacker to access sensitive information from the targeted system. 

2. Improper Authentication Bypass Vulnerability ( CVE-2020-9073   ) 

An Improper Authentication Bypass Vulnerability exists in Huawei
Smartphones due to insufficient validation of users identity in software.
In order to exploit this vulnerability, the attacker needs to have physical
access to the smartphone.
Successful exploitation of this vulnerability could allow the attacker to
bypass the limit of student mode function. 

Solution
Upgrade to latest version 

Vendor Information
Huawei
martphone-en
martphone-en

References
Huawei
martphone-en
martphone-en

CVE Name
CVE-2020-1808
CVE-2020-9073
Severity Rating: High 
Software Affected 
•Adobe DNG Software Development Kit (SDK) versions 1.5 and earlier 
Overview 
Multiple vulnerabilities have been reported in Adobe DNG Software
Development Kit (SDK) for Windows and macOS which could be exploited by an
attacker to conduct remote code execution attacks or obtain sensitive
information of the target system. 

Description
1. Multiple Heap Overflow Vulnerabilities ( CVE-2020-9589   CVE-2020-9590  
CVE-2020-9620   CVE-2020-9621   ) 

Multiple vulnerabilities exist in Adobe DNG Software Development Kit (SDK)
due to a heap-based overflow error. A remote attacker could exploit these
vulnerabilities by convincing the user to execute a specially crafted
application resulting in buffer overflow conditions.
Successful exploitation of these vulnerabilities could allow the attacker
to execute arbitrary code on the target system.

2. Multiple Out-of-Bounds Read Vulnerabilities ( CVE-2020-9622  
CVE-2020-9623   CVE-2020-9624   CVE-2020-9625.   CVE-2020-9626  
CVE-2020-9627   CVE-2020-9628   CVE-2020-9629   ) 

Multiple vulnerabilities exist in Adobe DNG Software Development Kit (SDK)
due to an out-of-bound read error. A remote attacker could exploit these
vulnerabilities by convincing the user to execute a specially crafted
application.
Successful exploitation of these vulnerabilities could allow the attacker
to obtain sensitive information on the target system.
Solution
Apply appropriate security updates as mentioned in the   Adobe Security
Advisory APSB20-26 
Vendor Information
Adobe

References
Adobe
Threatpost
digital-negative-sdk/155652/

CVE Name
CVE-2020-9589
CVE-2020-9590
CVE-2020-9620
CVE-2020-9621
CVE-2020-9622
CVE-2020-9623
CVE-2020-9624
CVE-2020-9625
CVE-2020-9626
CVE-2020-9627
CVE-2020-9628
CVE-2020-9629
Severity Rating: HIGH
Software Affected 
•Rails versions 6.0.3 and prior to 6.0.3
•Rails versions prior to 5.2.5 
•Rails versions prior to 6.0.4
•Rails versions prior to 5.2.4.2
•Rails versions prior to 6.0.3.1
Overview 
Multiple vulnerabilities have been reported in RAILS that could allow a
remote attacker to cause Cross-Site Request Forgery and bypass controls on
the targeted system. 

Description
1. Circumvention of file size limits in ActiveStorage ( CVE-2020-8162   ) 

This vulnerability exists in ActiveStorages S3 adapter that allows the
attacker to modify the Content-Length of a direct file upload. Successful
exploitation of this vulnerability could allow the attacker to control the
Content-Length of an S3 direct upload URL without receiving a new signature
from the server. This could be used to bypass controls in place on the
server to limit upload size. 

2. Possible Strong Parameters Bypass in ActionPack ( CVE-2020-8164   ) 

This vulnerability is due to a strong parameters bypass vector in
ActionPack. The user supplied information can be inadvertently leaked from
Strong Parameters in some cases.  Specifically the return value of
¿each¿, or ¿each_value¿,or¿each_pair¿ will return the underlying
"untrusted" hash of data that was read from the parameters.  Applications
that use this return value may inadvertently use untrusted user input. 

3. Potentially unintended unmarshalling of user-provided objects in
MemCacheStore and RedisCacheStore ( CVE-2020-8165   ) 

This vulnerability is due a potentially unexpected behaviour in the
MemCacheStore and RedisCacheStorewhile untrusted user input is written to
the cache store using the ¿raw: true¿ parameter.This will re-read the
result from the cache and can evaluate the user input as a Marshalled
object instead of plain text. Successful exploitation of this vulnerability
may allow a remote attacker to execute arbitrary code on the affected
system. The minimum impact is that this vulnerability allows the attacker
to inject untrusted Ruby objects into the web application. 

4. Cross-site request forgery(CSRF) Vulnerability in authenticity_token
meta tag ( CVE-2020-8166   ) 

By using a global CSRF token, such as the one present in the
authenticity_token meta tag, an attacker can forge a per-form CSRF token
for any action for that session. 

5. Cross-site request forgery(CSRF) Vulnerability in rails-ujs (
CVE-2020-8167   ) 

This vulnerability exists in rails-ujs that allows the attacker to send
CSRF tokens to wrong domains. By exploiting this vulnerability the attacker
is  able to control the href attribute of an anchor tag or the action
attribute of a form tag that will trigger a POST action. Successful
exploitation of this vulnerability could allow the attacker to set the href
or action to a cross-origin URL, and the CSRF token will be sent. 

Solution
Update to Rails 5.2.4.3 and 6.0.3.1
For more details refer vendor advisory at 
n-released/
Vendor Information

References


CVE Name
CVE-2020-8162
CVE-2020-8164
CVE-2020-8165
CVE-2020-8166
CVE-2020-8167
Severity Rating: HIGH
Software Affected 
•BIG-IP: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP LTM: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP AAM: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP AFM: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP Analytics: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP APM: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP ASM: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP DNS: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP FPS: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP GTM: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP Link Controller: 11.x, 12.x, 13.x, 14.x and 15.x
•BIG-IP PEM: 11.x, 12.x, 13.x, 14.x and 15.x

Overview 
Multiple vulnerabilities have been reported in F5 BIG-IP Products which
could be exploited by an attacker to execute arbitrary code, obtain
sensitive information and cause a Denial of Service (DOS) condition on the
targeted system. 

Description
1. Privileges Escalation Vulnerability ( CVE-2020-5896   ) 

This vulnerability exists due to weak permission of the BIG-IP Edge Client
Windows Installer Services temporary folder. Using this vulnerability, a
local attacker may execute "signed .exe" and MSI files.
Successful exploitation of this vulnerability could allow a local user to
escalate privileges on the targeted system. 

2. Use-after-free error vulnerability ( CVE-2020-5897   ) 

This vulnerability exists due to a use-after-free error in the BIG-IP Edge
Client Windows ActiveX component. A remote attacker could exploit this
vulnerability by enticing a user to open a specially crafted malicious
webpage, load it into the Internet Explorer browser by BIG-IP Edge Client
users to compromise the affected system.
Successful exploitation of this vulnerability could the remote attacker to
execute arbitrary code on the target system. 

3. Denial of Service Vulnerability ( CVE-2020-5898   ) 

This vulnerability exists due to improper sanitization of the pointer
received from the user land by BIG-IP Edge Client Windows Stonewall driver.
An attacker could exploit this vulnerability by sending a specially crafted
DeviceIoControl requests to a ¿\\.\urvpndrv¿ device and crash the Windows
kernel.
Successful exploitation of this vulnerability could allow the local
attacker to cause a Denial of Service (DoS) condition on the targeted
system. 

Solution
Apply appropriate fixes as issued by vendor in the following link: 



Vendor Information
F5 Networks

References
F5 Networks

CVE Name
CVE-2020-5896
CVE-2020-5897
CVE-2020-5898
Severity Rating: HIGH
Software Affected 
•Git 2.17.x versions 2.17.4 and prior
•Git 2.18.x versions 2.18.3 and prior
•Git 2.19.x versions 2.19.4 and prior
•Git 2.20.x versions 2.20.3 and prior
•Git 2.21.x versions 2.21.2 and prior
•Git 2.22.x versions 2.22.3 and prior
•Git 2.23.x versions 2.23.2 and prior
•Git 2.24.x versions 2.24.2 and prior
•Git 2.25.x versions 2.25.3 and prior
•Git 2.26.x versions 2.26.1 and prior

Overview 
A vulnerability has been reported in Git which could allow a remote
attacker to access stored credentials on a targeted system. 

Description
This vulnerability exists in Git due to improper handling of URLs used for
"credential helper" programs. A remote attacker could exploit this
vulnerability by feeding a specially crafted URL to Git running on an
affected system - either directly or through systems which automatically
clone URLs not visible to the user, such as Git sub modules, or package
systems built around Git. 

Successful exploitation of this vulnerability could allow the attacker to
access stored credentials on the targeted system. 

Solution
Upgrade to the patched versions as mentioned at: 

Vendor Information
Git
References


CVE Name
CVE-2020-11008
Severity Rating: HIGH
Software Affected 
•VMware Cloud Director version8.x
•VMware Cloud Director version 9.0.x
•VMware Cloud Director version 9.1.x
•VMware Cloud Director version 9.5.x
•VMware Cloud Director version 9.7.x
•VMware Cloud Director version 10.0.x
•VMware Cloud Director version 10.0.1

Overview 
A vulnerability has been reported in VMware Cloud Director which could
allow a remote attacker to execute arbitrary code on the targeted system. 

Description
This vulnerability exists in VMware Cloud Director due to improper handling
of input. A remote attacker could exploit this vulnerability by sending
malicious traffic through HTML5- and Flex-based UIs, the API Explorer
interface and API access. 

Successful exploitation of this vulnerability could allow a remote attacker
to execute arbitrary code on the target system. 

Solution
Apply appropriate fix as mentioned in VMwares Security Advisory: 

Vendor Information
VMware

References
VMware

CVE Name
CVE-2020-3956
Severity Rating: MEDIUM
Systems Affected 
•XiaomiMIUI V11.0.5.0.QFAEUXM

Overview 
Multiple Vulnerabilities have been reported in Xiaomi MIUI devices which
could allow a remote attacker to obtain sensitive information or install
apps on targeted device. 

Description
1.  Information Disclosure Vulnerability ( CVE-2020-9530   ) 

This vulnerability exists in Xiaomi MIUI devices due to the mishandling of
opening other components by the component GetApps (com.xiaomi.mipicks).An
attacker could exploit this vulnerability by persuading a victim to visit a
specially-crafted website.
Successful exploitation of this vulnerability could allow a remote attacker
to obtain sensitive information from the targeted device. 

2.  Code Execution Vulnerability ( CVE-2020-9531   ) 

This vulnerability exists in Xiaomi MIUI devices due to improper
verification of the local web pages parameters by GetApps. An adjacent
attacker could install apps and obtain sensitive information from targeted
unlocked device. 

Solution
Upgrade to Xiaomi MIUI2001122 or later 

Vendor Information
Xiaomi

References
Xiaomi
F-Secure

CVE Name
CVE-2020-9530
CVE-2020-9531
Severity Rating: MEDIUM

Software Affected 
•Microsoft Edge (Chromium-based) versions prior to 83.0.478.37

Overview 
A vulnerability has been reported in Microsoft Edge (Chromium-based) that
could allow a remote attacker to gain elevated privileges on a targeted
system. 
Description
This vulnerability exists in the affected software due to improper
validation of input by the Feedback extension.
Successful exploitation of this vulnerability could allow the attacker to
write files to arbitrary locations and gain elevated privileges on the
targeted system . 

Note: This vulnerability only exists in Chromium-based versions of
Microsoft Edge (which use Blink engine) and not the Edge HTML engine based
versions. 

Solution
Update to version 83.0.478.37 as mentioned at 
- -1195

Vendor Information
Microsoft
- -1195

References
Microsoft
- -1195
CyberSecurityHelp

CVE Name
Chromium-based)

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top