Severity Rating: HIGH

Software Affected

Mozilla Firefox versions prior to 84
Mozilla Firefox ESR versions prior to 78.6
Mozilla Thunderbird versions prior to 78.6
Overview

Multiple vulnerabilities have been reported in Mozilla products which could
allow a remote attacker to execute arbitrary code, perform spoofing
attacks, disclose potentially sensitive information, or cause denial of
service conditions on the targeted system.

Description

These vulnerabilities exist in Mozilla products due to uninitialized memory
error in BigInt, heap buffer overflow error or use-after-free in WebGL,
improper sanitization of CSS Sanitizer, use-after-free in
StyleGenericFlexBasis, improper security restrictions, improper processing
of user supplied input, error while using proxy.onRequest callback request
for view-source URLs, improper processing of downloaded files without
extensions. 

Successful exploitation of these vulnerabilities could allow a remote
attacker to execute arbitrary code, perform spoofing attacks, disclose
potentially sensitive information, or cause denial of service conditions on
the targeted system.

Solution

Upgrade to Mozilla Firefox version 84, Firefox ESR version 78.6 and
Thunderbird version 78.6
Vendor Information

Mozilla

References

Mozilla

CVE Name
CVE-2020-16042 
CVE-2020-26971
CVE-2020-26972
CVE-2020-26973
CVE-2020-26974
CVE-2020-26975
CVE-2020-26976
CVE-2020-26977
CVE-2020-26978
CVE-2020-26979
CVE-2020-35111
CVE-2020-35112
CVE-2020-35113
CVE-2020-35114
Severity Rating: HIGH

Systems Affected

Treck TCP/IP Stack version 6.0.1.67 and prior
Overview

Multiple vulnerabilities have been reported in Treck TCP/IP software, which
could be exploited by a remote attacker to perform Denial of Service (DoS)
attack or execute arbitrary code and take control of an affected system.

Description

Treck TCP/IP stack software is designed for and used in a variety of IoT
and embedded systems. The software can be licensed and integrated in
various ways, including compiled from source, licensed for modification and
reuse and finally as a dynamic or static linked library. 

These vulnerabilities exist due to buffer overflow in the Treck HTTP Server
component, out-of-bounds write in the IPv6 component, out-of-bound read in
the DHCPv6.A remote attacker could exploit these vulnerabilities by sending
specially crafted packets to the targeted system. Successful exploitation
of these vulnerabilities allow a remote attacker to perform denial of
service (DoS) attack or execute arbitrary code on the targeted system.

Solution

Update to the latest version (6.0.1.68) 


Vendor Information

Treck

References

Treck

CISA

CVE Name
CVE-2020-25066
CVE-2020-27337
CVE-2020-27338
CVE-2020-27336

Severity Rating: High

Systems Affected

uIP-Contiki-OS (end-of-life [EOL]), Version 3.0 and prior
uIP-Contiki-NG, Version 4.5 and prior
uIP (EOL), Version 1.0 and prior
open-iscsi, Version 2.1.12 and prior
picoTCP-NG, Version 1.7.0 and prior
picoTCP (EOL), Version 1.7.0 and prior
FNET, Version 4.6.3
Nut/Net, Version 5.1 and prior
Overview

Multiple Vulnerabilities have been reported in open source TCP/IP stacks
that could be exploited by a remote attacker to perform denial of service
(DoS) attack, execute arbitrary code or obtain sensitive information on the
targeted system.

Description

These vulnerabilities exist in four open source TCP/IP stacks (uIP, FNET,
picoTCP and Nut/Net) due to memory corruption in lightweight software
implementations in Real Time Operating Systems (RTOS) and IoT devices. A
remote unauthenticated attacker could exploit this vulnerability by sending
a specially-crafted network packets on the targeted system. 

Successful exploitation of these vulnerabilities could allow an attacker to
execute arbitrary code, gain access to sensitive information or perform
Denial of Service (DoS) attack on the targeted system.

Best practices while connecting IoT or embedded devices to a network 



Avoid exposure of IoT and embedded devices directly over the Internet and
use a segmented network zone when available.
Enable security features such as deep-packet inspection and firewall
anomaly detection when available to protect embedded and IoT devices.
Ensure secure defaults are adopted and disable unused features and services
on your embedded devices.
Regularly update firmware to the vendor provided latest stable version to
ensure your device is up to date.




Solution

FNET users update to Version 4.7.0 or later   
uIP-Contiki-NG users update to the latest version available at   
open-iscsi users update to the latest version available at   
Maintainers of Nut/Net can update the latest version available at   

Vendor Information

uIP
PicoTCP
FNET
Nut/OS
iscsi
- -8rgp
Microchip
nerability-response/amnesia-network-stack-vulnerability

References

NJCCIC
ous-opensource-tcpip-stacks

US CERT

SIEMENS

FEIG
8-01_SecurityAdvisory.pdf

forescout

IoTSecurityFoundation

CVE Name
CVE-2020-13984
CVE-2020-13985
CVE-2020-13986
CVE-2020-13987
CVE-2020-13988
CVE-2020-17437
CVE-2020-17438
CVE-2020-17439
CVE-2020-17440
CVE-2020-17441
CVE-2020-17442
CVE-2020-17443
CVE-2020-17444
CVE-2020-17445
CVE-2020-17467
CVE-2020-17468
CVE-2020-17469
CVE-2020-17470
CVE-2020-24334
CVE-2020-24335
CVE-2020-24336
CVE-2020-24337
CVE-2020-24338
CVE-2020-24339
CVE-2020-24340
CVE-2020-24383
CVE-2020-25107
CVE-2020-25108
CVE-2020-25109
CVE-2020-25110
CVE-2020-25111
CVE-2020-25112
Severity Rating: HIGH

Software Affected

Contact Form 7 5.3.1 and older versions
Overview

A vulnerability has been discovered in Contact Form 7 version 5.3.1 or
older that allows an attacker to upload malicious scripts.

Description

An unrestricted file upload vulnerability is found in a Word Press plug-in.
 An attacker can exploit this vulnerability to upload arbitrary code and
run it in the context of the web server process. This may facilitate
unauthorized access or privilege escalation. It allows an unauthenticated
user to bypass any form file-type restrictions in Contact Form 7 and upload
an executable binary to a site running the plug-in version 5.3.1 or
earlier. 

Successful exploitation of this vulnerability could allow the attacker to
bypass any form file-type restrictions in Contact Form 7.

Solution

Update to Contact Form 7 5.3.2 


Vendor Information

Word Press

References

Acunetix
7-arbitrary-file-upload-3-5-2/

Searchenginejournal
on-sites/391111/

Threatpost

Security newspaper
wordpress-sites-affected-by-critical-vulnerability/

Tenable

CVE Name
CVE-2020-35489

Severity Rating: HIGH

Software Affected

Foxit Reader versions 10.1.0.37527 and earlier
Foxit Phantom PDF versions 10.1.0.37527 and earlier
Overview

Multiple vulnerabilities have been reported in Foxit Reader and Phantom PDF
which could allow a remote attacker to cause Out-of-Bounds Write Remote
Code Execution, Type Confusion Memory Corruption, denial of service
condition or execute arbitrary code on the target system.

Description

These vulnerabilities exist due to insufficient validation of objects,
incorrect processing of PDF files, lack of proper validation when an
incorrect argument is passed to the app.media.openPlayer function, access
or use of a deleted pointer and array overflow issue. A remote attacker
could exploit these vulnerabilities by sending specially crafted malicious
file on the target system. 

Successful exploitation of these vulnerabilities could allow the attacker
to cause Out-of-Bounds Write Remote Code Execution, Type Confusion Memory
Corruption, denial of service condition or execute arbitrary code on the
target system.

Solution

Upgrade to the Foxit Reader 10.1.1 and Foxit Phantom PDF 10.1.1 


Vendor Information

Foxit Software

References

Foxit Software

CyberSecurityHelp

CVE Name
CVE-2020-27860
CVE-2020-13547
CVE-2020-13548
CVE-2020-13557
CVE-2020-13560
CVE-2020-13570
CVE-2020-28203
Severity Rating: HIGH

Software Affected

Google Android OS builds utilizing Security Patch Levels issued prior to
May 5, 2019
Overview

Multiple vulnerabilities have been reported in Google Android operating
system (OS) which could enable a remote attacker to perform arbitrary code
execution, gain elevated privileges, obtain sensitive information and cause
denial of service condition on the targeted system.

Description

These vulnerabilities exists in Google Android due to flaws in the Media
Framework, System component, Kernel component, Broadcom components,
MediaTek components, Qualcomm components and Qualcomm closed-source
components. A remote attacker could exploit these vulnerabilities by
hosting a specially crafted file designed to exploit the vulnerabilities. 

Successful exploitation of these vulnerabilities could allow remote
attacker to perform arbitrary code execution within the context of a
privileged process, gain elevated privileges, allow the attacker to access
sensitive information from the targeted device and cause denial of service
conditions on the targeted system.

Solution

Apply appropriate over-the-air updates as provided by various device
manufacturers. 


Vendor Information

Google Android

References

Google Android

Center for Internet Security
oid-os-could-allow-for-remote-code-execution_2020-162/

CVE Name
CVE-2020-0099
CVE-2020-0294
CVE-2020-0440
CVE-2020-0459
CVE-2020-0464
CVE-2020-0467
CVE-2020-0468
CVE-2020-0469
CVE-2020-0458
CVE-2020-0470
CVE-2020-0460
CVE-2020-0463
CVE-2020-15802
CVE-2020-0444
CVE-2020-0465
CVE-2020-0466
CVE-2020-0016
CVE-2020-0019
CVE-2020-0455
CVE-2020-0456
CVE-2020-0457
CVE-2020-11225
CVE-2020-11146
CVE-2020-11167
CVE-2020-11185
CVE-2020-11217
CVE-2020-3685
CVE-2020-3686
CVE-2020-3691
CVE-2020-11136
CVE-2020-11137
CVE-2020-11138
CVE-2020-11140
CVE-2020-11143
CVE-2020-11119
CVE-2020-11139
CVE-2020-11144
CVE-2020-11145
CVE-2020-11179
CVE-2020-11197
CVE-2020-11200
CVE-2020-11212
CVE-2020-11213
CVE-2020-11214
CVE-2020-11215
CVE-2020-11216
Severity Rating: High

Systems Affected

SolarWinds Orion Platform versions 2019.4 HF 5 and 2020.2 with no hotfix or
with 2020.2 HF 1, including:

Application Centric Monitor (ACM)
Database Performance Analyzer Integration Module (DPAIM)
Enterprise Operations Console (EOC)
High Availability (HA)
IP Address Manager (IPAM)
Log Analyzer (LA)
Network Automation Manager (NAM)
Network Configuration Manager (NCM)
Network Operations Manager (NOM)
Network Performance Monitor (NPM)
NetFlow Traffic Analyzer (NTA)
Server & Application Monitor (SAM)
Server Configuration Monitor (SCM)
Storage Resource Monitor (SCM)
User Device Tracker (UDT)
Virtualization Manager (VMAN)
VoIP & Network Quality Manager (VNQM)
Web Performance Monitor (WPM)
Overview

A vulnerability has been reported on the SolarWinds' Orion IT monitoring
and management software, which could allow a remote attacker to bypass
authentication and execute API commands which may result in a compromise of
the SolarWinds instance.

Description

This vulnerability exists due to an error while processing authentication
requests within the SolarWinds Orion API. An unauthenticated, remote
attacker could exploit this vulnerability by creating specially crafted
parameters within the "Request.PathInfo" URI component and setting the
"SkipAuthentication" flag. 

Successful exploitation of this vulnerability allow the attacker to bypass
authentication and execute API commands which may result in compromise of
the SolarWinds instance. 

Note: It is reported that this vulnerability is being exploited in the
wild.



Solution

Organisations are recommended to apply updates to the latest versions of
the SolarWinds Orion Platform mentioned in the SolarWinds Security
Advisory:

2019.4 HF 6 
2020.2.1 HF 2 
2019.2 SUPERNOVA Patch 
2018.4 SUPERNOVA Patch 
2018.2 SUPERNOVA Patch
Users who have already upgraded to 2020.2.1 HF 2 or 2019.4 HF 6 versions,
no further action is required. 

Affected users who are unable to install the security updates immediately
are advised to temporarily protect their environment by applying mitigating
measures recommended by SolarWinds Supernova Mitigation.   


Recommendations 

Organisations are strongly advised to take additional measure like:

Orion Platform versions 2019.4 HF6 and 2020.2.1 HF2 were designed to
protect from both SUNBURST and SUPERNOVA
All active maintenance customers of Orion Platform products, except those
customers already on Orion Platform versions 2019.4 HF 6 or 2020.2.1 HF 2,
apply the latest updates related to the version of the product they have
deployed, as soon as possible.These updates contain security enhancements
including those designed to protect you from SUNBURST and SUPERNOVA.
Analyze all configuration for network devices managed by the Orion platform
for alteration.
Run up to date antivirus or EDR products that detect compromised SolarWinds
libraries and potentially anomalous process behaviour by these binaries.
Consider disabling SolarWinds in your environment entirely until you are
confident that you have a trustworthy build free of injected code.
Block all traffic to and from hosts where any version of SolarWinds Orion
software has been installed.
Identify and remove threat-actor controlled accounts and persistence
mechanisms.
Reset all credentials used by SolarWinds software and implement a rotation
policy for these accounts. 
Affected organizations should determine the need to change credentials on
all devices being managed by the affected SolarWinds platform. This
includes:
User credentials
SNMP community strings
IKE pre-shared keys§
Shared secrets for TACACS, TACACS+ and RADIUS
Secrets for BGP, OSPF, EIGRP or other routing protocols
Exportable RSA keys and certificates for SSH or other protocols
Organisations should consider the impacts and applicability of these steps
on their specific network operations prior to implementing these
mitigations.  

Vendor Information



References

SolarWinds
t/core-secure-configuration.htm

US CERT
on-solarwinds-software

Palo Alto Networks

Microsoft
p-based-kerberoasting-with-azure-atp/ba-p/462448
rotected-from-solorigate/
on-state-cyber-attacks/

CVE Name
CVE-2020-10148

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top