Severity Rating: MEDIUM

Software Affected

Entity Registration module version prior 7.1.9
Overview

A vulnerability has been reported in Entity registration module of Drupal which could allow an attacker to bypass security restrictions on targeted system.

Description

This vulnerability exists in the Entity registration module due to insufficient restrict update access. An attacker could exploit this vulnerability with "update own [registration type]" permission to gain unauthorized access.

Successful exploitation of this vulnerability could allow an attacker to bypass and manage security restrictions.

Solution

Apply appropriate upgrade as mentioned:


Vendor Information

Drupal

References

Drupal

 

Severity Rating: HIGH

Software Affected

FortiOS version 7.2.0 through 7.2.1
FortiOS version 7.0.0 through 7.0.7
FortiOS version 6.4.0 through 6.4.9
FortiOS version 6.2 all versions
FortiOS version 6.0 all versions
FortiProxy version 7.0.0 through 7.0.6
FortiProxy version 2.0.0 through 2.0.10
FortiProxy version 1.2.0 all versions
Overview

A vulnerability has been reported in FortiOS and FortiProxy, which could allow an unauthenticated remote attacker to bypass security restrictions on the targeted system.

Description

This vulnerability exists in Fortinet Devices due to authentication bypass by assumed-immutable data vulnerability in the FortiOS SSH login component. An attacker can exploit this vulnerability by sending specially crafted Access-Challenge response from the Radius server.

Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to Bypass security restrictions on the targeted system.

Solution

Upgrade to the latest versions of FortiOS and FortiProxy as mentioned in the vendor advisory


Vendor Information

Fortiguard

References

 

CVE Name
CVE-2022-35843

 

Severity Rating: High

Software Affected

Microsoft Windows
Microsoft Office
Microsoft.Net
Microsoft Azure
Microsoft SharePoint
Microsoft 365
Microsoft Exchange Server
Microsoft Visual Studio
Overview

Multiple vulnerabilities have been reported in Microsoft Products, which could allow an attacker to gain elevated privileges, obtain sensitive information, conduct remote code execution attacks, bypass security restrictions, conduct spoofing attacks, or cause denial of service conditions.

Description

Multiple vulnerabilities have been reported in various Microsoft products.

Solution

Apply appropriate security updates as mentioned in:  

Vendor Information

Microsoft

References

 

 

Severity Rating: HIGH

Software Affected

Mozilla Firefox Thunderbird versions prior to 102.5.1
Overview

A vulnerability has been reported in Mozilla Thunderbird which could allow a remote attacker to perform arbitrary code execution on the targeted system.

Description

This vulnerability exists in Mozilla Thunderbird due to quoting from an HTML email with certain tags. A remote attacker could exploit this vulnerability by persuading a victim to visit a specially crafted web request.

Successful exploitation of this vulnerability could allow a remote attacker to perform arbitrary code execution on the targeted system.

Solution

Upgrade to Mozilla Firefox Thunderbird versions 102.5.1
Vendor Information

Mozilla Thunderbird

References

Mozilla Thunderbird

CVE Name
CVE-2022-45414

 

Severity Rating: HIGH

Software Affected

VMware ESXi version prior to 8.0
VMware vCenter Server versions prior to 8.0
VMware Cloud Foundation (vCenter Server) version 4.x and prior
VMware Cloud Foundation (ESXi) version 4.x and prior
Overview

Multiple vulnerabilities have been reported in VMware ESXi and vCenter Server which could allow an attacker to trigger memory corruption, disclose sensitive information and cause denial of service condition on the targeted system.

Description

1. VMware ESXi memory corruption vulnerability ( CVE-2022-31696   )

This vulnerability exists in VMware ESXi due to a boundary error in the way network socket are handled. A local attacker with access to ESXi could exploit this vulnerability to trigger memory corruption and execute arbitrary code with elevated privileges on the targeted system.

2. VMware vCenter Server information disclosure vulnerability ( CVE-2022-31697   )

This vulnerability exists in VMware vCenter server due to the logging of credentials in plain text. A local attacker with access to a workstation that invoked a vCenter Server Appliance ISO operation could exploit this vulnerability to disclose sensitive information on the targeted system.

3. VMware vCenter Server denial of service vulnerability ( CVE-2022-31698   )

This vulnerability exists in VMware vCenter Server due to insufficient validation of user-supplied input in the content library service when handling HTTP headers. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP request to port 443/tcp. Successful exploitation of this vulnerability could allow a remote attacker to cause a denial of service (DoS) condition on the targeted system.

4. VMware ESXi OpenSLP heap overflow vulnerability ( CVE-2022-31699   )

This vulnerability exists in VMware ESXi due to a boundary error in OpenSLP. A local attacker with restricted privileges within a sandbox process could exploit this vulnerability to trigger a heap overflow and gain access to sensitive information on the targeted system.

Solution

Apply appropriate updates as mentioned by the vendor:


Vendor Information

VMware

References

VMware

CVE Name
CVE-2022-31696
CVE-2022-31697
CVE-2022-31698
CVE-2022-31699
Severity Rating: HIGH

Software Affected

F5 BIG-IP (all modules) versions (17.0.0, 16.1.0 - 16.1.3, 15.1.0 - 15.1.8, 14.1.0 - 14.1.5, 13.1.0 - 13.1.5)
BIG-IQ Centralized Management versions (7.0.0 - 7.1.0, 8.0.0 - 8.2.0)
Traffix SDC versions (5.1.0, 5.2.0)
Overview

A vulnerability has been reported in the F5 Products which may allow an authenticated attacker to access sensitive information, data manipulation and cause denial of service condition on the targeted system.

Description

This vulnerability exists in the F5 Products due to flaw in Linux kernel¿s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. An attacker could exploit this vulnerability by persuading a victim to visit a specially crafted request.

Successful exploitation of this vulnerability may allow an authenticated attacker to access sensitive information, data manipulation and cause denial of service condition on the targeted system.

Solution

Apply appropriate update as mentioned by the vendor.


Vendor Information

F5 Products

References

F5 Products

CVE Name
CVE-2022-0492
Multiple vulnerabilities in Omron NJ/NX series Machine Automation Controllers 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

NX7-series Machine Automation Controller versions prior to 1.28 (All Models)
NX1-series Machine Automation Controller versions prior to 1.48 (All Models)
NJ-series Machine Automation Controller versions prior to 1.48 (All Models)
Automation Software Sysmac Studio versions prior to 1.49 (All Models)
NA-series Programable Terminal Runtime versions prior to 1.15 (NA5-15W, NA5-12W, NA5-9W, NA5-7W)
Overview

Multiple vulnerabilities have been reported in Omron NJ/NX series Machine Automation Controllers products which could allow the attacker to bypass authentication, perform unauthorized access, execute arbitrary code, and cause a denial of service (DoS) condition on the targeted system.

Description

These vulnerabilities exist in Omron NJ/NX series Machine Automation Controllers products due to hard-coded credentials, authentication bypass by capture-replay, and active debug code vulnerabilities. An attacker could exploit these vulnerabilities by analyzing the communication between the controller and the specific software used by Omron internally.
Successful exploitation of these vulnerabilities could allow the attacker to bypass authentication, perform unauthorized access, execute arbitrary code, and cause a denial of service (DoS) condition on the targeted system.

Note: It has been reported that vulnerabilities are being exploited.

Solution

Apply appropriate software updates as mentioned in the Omron Security updates.



Vendor Information

Omron

References

 

CVE Name
CVE-2022-33208
CVE-2022-33971
CVE-2022-34151




© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top