Severity Rating: HIGH

Software Affected

Mozilla Firefox Thunderbird versions prior to 102.5.1
Overview

A vulnerability has been reported in Mozilla Thunderbird which could allow a remote attacker to perform arbitrary code execution on the targeted system.

Description

This vulnerability exists in Mozilla Thunderbird due to quoting from an HTML email with certain tags. A remote attacker could exploit this vulnerability by persuading a victim to visit a specially crafted web request.

Successful exploitation of this vulnerability could allow a remote attacker to perform arbitrary code execution on the targeted system.

Solution

Upgrade to Mozilla Firefox Thunderbird versions 102.5.1
Vendor Information

Mozilla Thunderbird

References

Mozilla Thunderbird

CVE Name
CVE-2022-45414

 

Severity Rating: HIGH

Software Affected

VMware ESXi version prior to 8.0
VMware vCenter Server versions prior to 8.0
VMware Cloud Foundation (vCenter Server) version 4.x and prior
VMware Cloud Foundation (ESXi) version 4.x and prior
Overview

Multiple vulnerabilities have been reported in VMware ESXi and vCenter Server which could allow an attacker to trigger memory corruption, disclose sensitive information and cause denial of service condition on the targeted system.

Description

1. VMware ESXi memory corruption vulnerability ( CVE-2022-31696   )

This vulnerability exists in VMware ESXi due to a boundary error in the way network socket are handled. A local attacker with access to ESXi could exploit this vulnerability to trigger memory corruption and execute arbitrary code with elevated privileges on the targeted system.

2. VMware vCenter Server information disclosure vulnerability ( CVE-2022-31697   )

This vulnerability exists in VMware vCenter server due to the logging of credentials in plain text. A local attacker with access to a workstation that invoked a vCenter Server Appliance ISO operation could exploit this vulnerability to disclose sensitive information on the targeted system.

3. VMware vCenter Server denial of service vulnerability ( CVE-2022-31698   )

This vulnerability exists in VMware vCenter Server due to insufficient validation of user-supplied input in the content library service when handling HTTP headers. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP request to port 443/tcp. Successful exploitation of this vulnerability could allow a remote attacker to cause a denial of service (DoS) condition on the targeted system.

4. VMware ESXi OpenSLP heap overflow vulnerability ( CVE-2022-31699   )

This vulnerability exists in VMware ESXi due to a boundary error in OpenSLP. A local attacker with restricted privileges within a sandbox process could exploit this vulnerability to trigger a heap overflow and gain access to sensitive information on the targeted system.

Solution

Apply appropriate updates as mentioned by the vendor:


Vendor Information

VMware

References

VMware

CVE Name
CVE-2022-31696
CVE-2022-31697
CVE-2022-31698
CVE-2022-31699
Severity Rating: HIGH

Software Affected

F5 BIG-IP (all modules) versions (17.0.0, 16.1.0 - 16.1.3, 15.1.0 - 15.1.8, 14.1.0 - 14.1.5, 13.1.0 - 13.1.5)
BIG-IQ Centralized Management versions (7.0.0 - 7.1.0, 8.0.0 - 8.2.0)
Traffix SDC versions (5.1.0, 5.2.0)
Overview

A vulnerability has been reported in the F5 Products which may allow an authenticated attacker to access sensitive information, data manipulation and cause denial of service condition on the targeted system.

Description

This vulnerability exists in the F5 Products due to flaw in Linux kernel¿s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. An attacker could exploit this vulnerability by persuading a victim to visit a specially crafted request.

Successful exploitation of this vulnerability may allow an authenticated attacker to access sensitive information, data manipulation and cause denial of service condition on the targeted system.

Solution

Apply appropriate update as mentioned by the vendor.


Vendor Information

F5 Products

References

F5 Products

CVE Name
CVE-2022-0492
Multiple vulnerabilities in Omron NJ/NX series Machine Automation Controllers 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

NX7-series Machine Automation Controller versions prior to 1.28 (All Models)
NX1-series Machine Automation Controller versions prior to 1.48 (All Models)
NJ-series Machine Automation Controller versions prior to 1.48 (All Models)
Automation Software Sysmac Studio versions prior to 1.49 (All Models)
NA-series Programable Terminal Runtime versions prior to 1.15 (NA5-15W, NA5-12W, NA5-9W, NA5-7W)
Overview

Multiple vulnerabilities have been reported in Omron NJ/NX series Machine Automation Controllers products which could allow the attacker to bypass authentication, perform unauthorized access, execute arbitrary code, and cause a denial of service (DoS) condition on the targeted system.

Description

These vulnerabilities exist in Omron NJ/NX series Machine Automation Controllers products due to hard-coded credentials, authentication bypass by capture-replay, and active debug code vulnerabilities. An attacker could exploit these vulnerabilities by analyzing the communication between the controller and the specific software used by Omron internally.
Successful exploitation of these vulnerabilities could allow the attacker to bypass authentication, perform unauthorized access, execute arbitrary code, and cause a denial of service (DoS) condition on the targeted system.

Note: It has been reported that vulnerabilities are being exploited.

Solution

Apply appropriate software updates as mentioned in the Omron Security updates.



Vendor Information

Omron

References

 

CVE Name
CVE-2022-33208
CVE-2022-33971
CVE-2022-34151




 

CURRENT ACTIVITIES 
Threat actors exploiting authentication bypass vulnerability in Fortinet Products
Indian - Computer Emergency Response Team (cert-in.org.in)


It is reported that threat actors are actively exploiting an authentication bypass vulnerability in Fortinet Products. The vulnerability allows the attacker to gain access to administrative interface and perform actions via a specially crafted request.

Software Affected

Forti OS versions 7.0.0 to 7.0.6 and 7.2.0 to 7.2.1
Forti Proxy versions 7.0.0 to 7.0.6 and 7.2.0
Forti Switch Manager versions 7.2.0 and 7.0.0
Description

This vulnerability exists in FortiOS, FortiProxy and FortiSwitchManager due to an authentication error. An attacker could exploit this vulnerability by sending a specially crafted HTTP/HTTPS request to the target user and adding a SSH key to the admin user. The attacker gains access to the SSH into the affected system as admin.

Successful exploitation of this vulnerability could allow the attacker to bypass security restrictions and gain complete access to the target system.

Note: It is to be noted that this vulnerability is being exploited in the Wild in case the patches are not updated.

Solution

Upgrade to the latest versions of FortiOS, FortiProxy and FortiSwitchManager as mentioned in the vendor advisory:


Vendor Information

Fortiguard

Reference


CVE Name
CVE-2022-40684

 

Multiple vulnerabilities in Mozilla Products 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Mozilla Firefox versions prior to 107
Mozilla Firefox ESR versions prior to 102.5
Mozilla Thunderbird versions prior to 102.5
Overview

Multiple vulnerabilities have been reported in Mozilla products, which
could allow an attacker to bypass security restrictions, execute arbitrary
code, gain access to potentially sensitive information, perform Cross-Site
Scripting (XSS) attacks, perform spoofing attacks or cause a denial of
service (DoS) condition on the targeted system.

Description

These vulnerabilities exist in Mozilla Products due to cross-origin policy
violations, a flaw in the handling of a series of popups and window.print()
events, Use-after-free in Input Stream implementation, Java Script Realm,
Garbage collection, expat, a use-after-free while loading a font using
FontFace(), an error when handling Same Site cookies, non-standard headers,
a boundary condition when resolving a symlink such as
file:///proc/self/fd/1, insecure handling of downloaded files, Keystroke
Side-Channel Leakage, incorrect detection of private browsing mode by
Service Workers, incorrect processing of custom mouse cursor, improper
handling deletion of a security exception granted for an invalid TLS
certificate, tables inside of an iframe and memory corruption error. A
remote attacker could exploit these vulnerabilities by persuading a victim
to visit a specially-crafted Web site.

Successful exploitation of these vulnerabilities could allow a remote
attacker to bypass security restrictions, execute arbitrary code, gain
access to potentially sensitive information, perform Cross-Site Scripting
(XSS) attacks, perform spoofing attacks or cause a denial of service (DoS)
condition on the targeted system.

Solution

Apply appropriate software updates as mentioned in the Mozilla Security
Advisory:




Vendor Information

Mozilla

References

Mozilla

CVE Name
CVE-2022-45403
CVE-2022-45404
CVE-2022-45405
CVE-2022-45406
CVE-2022-45407
CVE-2022-45408
CVE-2022-45409
CVE-2022-45410
CVE-2022-45411
CVE-2022-45412
CVE-2022-45413
CVE-2022-40674
CVE-2022-45415
CVE-2022-45416
CVE-2022-45417
CVE-2022-45418
CVE-2022-45419
CVE-2022-45420
CVE-2022-45421


 

Denial of Service Vulnerability in RUGGEDCOM ROS V4 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: MEDIUM

Software Affected

RUGGEDCOM ROS i800 V4.X: All versions
RUGGEDCOM ROS i801 V4.X: All versions
RUGGEDCOM ROS i802 V4.X: All versions
RUGGEDCOM ROS i803 V4.X: All versions
RUGGEDCOM ROS RMC30 V4.X: All versions
RUGGEDCOM ROS RMC8388 V4.X: All versions
RUGGEDCOM ROS RP110 V4.X: All versions
RUGGEDCOM ROS RS400 V4.X: All versions
RUGGEDCOM ROS RS401 V4.X: All versions
RUGGEDCOM ROS RS416Pv2 V4.X: All versions
RUGGEDCOM ROS RS416v2 V4.X: All versions
RUGGEDCOM ROS RS900 (32M) V4.X: All versions
RUGGEDCOM ROS RS900 V4.X: All versions
RUGGEDCOM ROS RS900G (32M) V4.X: All versions
RUGGEDCOM ROS RS900G V4.X: All versions
RUGGEDCOM ROS RS900GP V4.X: All versions
RUGGEDCOM ROS RS900L V4.X: All versions
RUGGEDCOM ROS RS900M V4.X: All versions
RUGGEDCOM ROS RS900W V4.X: All versions
RUGGEDCOM ROS RS910 V4.X: All versions
RUGGEDCOM ROS RS910L V4.X: All versions
RUGGEDCOM ROS RS910W V4.X: All versions
RUGGEDCOM ROS RS920L V4.X: All versions
RUGGEDCOM ROS RS920W V4.X: All versions
RUGGEDCOM ROS RS930L V4.X: All versions
RUGGEDCOM ROS RS930W V4.X: All versions
RUGGEDCOM ROS RS940G V4.X: All versions
RUGGEDCOM ROS RS1600 V4.X: All versions
RUGGEDCOM ROS RS1600F V4.X: All versions
RUGGEDCOM ROS RS1600T V4.X: All versions
RUGGEDCOM ROS RS8000 V4.X: All versions
RUGGEDCOM ROS RS8000A V4.X: All versions
RUGGEDCOM ROS RS8000H V4.X: All versions
RUGGEDCOM ROS RS8000T V4.X: All versions
RUGGEDCOM ROS RSG920P V4.X: All versions
RUGGEDCOM ROS RSG2100 (32M) V4.X: All versions
RUGGEDCOM ROS RSG2100 V4.X: All versions
RUGGEDCOM ROS RSG2100P V4.X: All versions
RUGGEDCOM ROS RSG2200 V4.X: All versions
RUGGEDCOM ROS RSG2288 V4.X: All versions
RUGGEDCOM ROS RSG2300 V4.X: All versions
RUGGEDCOM ROS RSG2300P V4.X: All versions
RUGGEDCOM ROS RSG2488 V4.X: All versions
Overview

A vulnerability has been reported in Siemen products which could allow a
remote attacker to cause a Denial-of-service condition (slowloris) on the
targeted system.

Description

This vulnerability exists in Siemen products due to improper input
validation in the RUGGEDCOM ROS-based V4 devices. A remote attacker could
exploit this vulnerability by sending a crafted HTTP request to the web
interface of an affected device.

Successful exploitation of this vulnerability could allow a remote attacker
to cause a Denial-of-service condition (slowloris) on the targeted system.

Workaround

The user may apply the following workaround to reduce the risk, as provided
by the vendor.

Restrict access to port 80/tcp and 443/tcp to trusted IP addresses only.
Deactivate the webserver if not required, and if deactivation is supported
by the product.
Vendor Information

SIEMENS

References

SIEMENS

CVE Name
CVE-2022-39158


© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top