Severity Rating: HIGH

Software Affected

F5 BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link
Controller, PEM)

16.x versions 16.0.0
15.x versions 15.0.0 - 15.1.0
14.x versions 14.1.0 - 14.1.2
13.x versions 13.1.0 - 13.1.3
12.x versions 12.1.0 - 12.1.5
11.x versions 11.6.1 - 11.6.5
Overview

A reflected cross site scripting vulnerability has been reported in F5
BIG-IP Products which could allow an attacker to perform cross-site
scripting (XSS) attack on the target system resulting in a complete
compromise of the BIG-IP system if the victim user is granted the admin
role.

Description

This vulnerability exists in multiple F5 BIG-IP products due to undisclosed
endpoints in iControl REST feature. A remote attacker can exploit this
vulnerability using a crafted URL to a reflected cross-site scripting (XSS)
in an undisclosed page of the Configuration utility. 

Successful exploitation of the vulnerability could allow an attacker to
perform cross-site scripting (XSS) attack on the target system resulting in
a complete compromise of the BIG-IP system if the victim user is granted
the admin role.

Solution

Upgrade to fixed versions as mentioned in the F5 Advisory


Vendor Information

F5 Networks

References

F5 Networks

Tenable

CVE Name
CVE-2020-5948
Severity Rating: HIGH
Systems Affected

GE Imaging and Ultrasound Products
Overview

A vulnerability has been reported in GE Imaging and Ultrasound Products
which could allow a remote attacker to gain access or modify the sensitive
information on the targeted system.

Description

1. Information Disclosure Vulnerability ( CVE-2020-25175   ) 

This vulnerability exists in GE Healthcare Imaging and Ultrasound Products
due to unprotected transport of credentials. A remote attacker could
exploit this vulnerability by gaining access to the network.
Successful exploitation of this vulnerability could allow attacker to gain
access to sensitive information on the targeted system. 

2. Information Disclosure Vulnerability ( CVE-2020-25179   ) 

This vulnerability exists in GE Healthcare Imaging and Ultrasound Products
because they allow exposed/default credentials to be utilized to access the
system. An attacker could exploit this vulnerability by gaining access to
the network. 
Successful exploitation of this vulnerability could allow attacker to gain
access or modify the sensitive information on the targeted system.

Solution

GE recommends users refer to the GE Healthcare Product Security Portal. 


Vendor Information

GE Healthcare

References

GE Healthcare

CVE Name
CVE-2020-25175
CVE-2020-25179
Severity Rating: HIGH

Software Affected

Mozilla Firefox versions prior to 84
Mozilla Firefox ESR versions prior to 78.6
Mozilla Thunderbird versions prior to 78.6
Overview

Multiple vulnerabilities have been reported in Mozilla products which could
allow a remote attacker to execute arbitrary code, perform spoofing
attacks, disclose potentially sensitive information, or cause denial of
service conditions on the targeted system.

Description

These vulnerabilities exist in Mozilla products due to uninitialized memory
error in BigInt, heap buffer overflow error or use-after-free in WebGL,
improper sanitization of CSS Sanitizer, use-after-free in
StyleGenericFlexBasis, improper security restrictions, improper processing
of user supplied input, error while using proxy.onRequest callback request
for view-source URLs, improper processing of downloaded files without
extensions. 

Successful exploitation of these vulnerabilities could allow a remote
attacker to execute arbitrary code, perform spoofing attacks, disclose
potentially sensitive information, or cause denial of service conditions on
the targeted system.

Solution

Upgrade to Mozilla Firefox version 84, Firefox ESR version 78.6 and
Thunderbird version 78.6
Vendor Information

Mozilla

References

Mozilla

CVE Name
CVE-2020-16042 
CVE-2020-26971
CVE-2020-26972
CVE-2020-26973
CVE-2020-26974
CVE-2020-26975
CVE-2020-26976
CVE-2020-26977
CVE-2020-26978
CVE-2020-26979
CVE-2020-35111
CVE-2020-35112
CVE-2020-35113
CVE-2020-35114
Severity Rating: HIGH

Systems Affected

Treck TCP/IP Stack version 6.0.1.67 and prior
Overview

Multiple vulnerabilities have been reported in Treck TCP/IP software, which
could be exploited by a remote attacker to perform Denial of Service (DoS)
attack or execute arbitrary code and take control of an affected system.

Description

Treck TCP/IP stack software is designed for and used in a variety of IoT
and embedded systems. The software can be licensed and integrated in
various ways, including compiled from source, licensed for modification and
reuse and finally as a dynamic or static linked library. 

These vulnerabilities exist due to buffer overflow in the Treck HTTP Server
component, out-of-bounds write in the IPv6 component, out-of-bound read in
the DHCPv6.A remote attacker could exploit these vulnerabilities by sending
specially crafted packets to the targeted system. Successful exploitation
of these vulnerabilities allow a remote attacker to perform denial of
service (DoS) attack or execute arbitrary code on the targeted system.

Solution

Update to the latest version (6.0.1.68) 


Vendor Information

Treck

References

Treck

CISA

CVE Name
CVE-2020-25066
CVE-2020-27337
CVE-2020-27338
CVE-2020-27336

Severity Rating: High

Systems Affected

uIP-Contiki-OS (end-of-life [EOL]), Version 3.0 and prior
uIP-Contiki-NG, Version 4.5 and prior
uIP (EOL), Version 1.0 and prior
open-iscsi, Version 2.1.12 and prior
picoTCP-NG, Version 1.7.0 and prior
picoTCP (EOL), Version 1.7.0 and prior
FNET, Version 4.6.3
Nut/Net, Version 5.1 and prior
Overview

Multiple Vulnerabilities have been reported in open source TCP/IP stacks
that could be exploited by a remote attacker to perform denial of service
(DoS) attack, execute arbitrary code or obtain sensitive information on the
targeted system.

Description

These vulnerabilities exist in four open source TCP/IP stacks (uIP, FNET,
picoTCP and Nut/Net) due to memory corruption in lightweight software
implementations in Real Time Operating Systems (RTOS) and IoT devices. A
remote unauthenticated attacker could exploit this vulnerability by sending
a specially-crafted network packets on the targeted system. 

Successful exploitation of these vulnerabilities could allow an attacker to
execute arbitrary code, gain access to sensitive information or perform
Denial of Service (DoS) attack on the targeted system.

Best practices while connecting IoT or embedded devices to a network 



Avoid exposure of IoT and embedded devices directly over the Internet and
use a segmented network zone when available.
Enable security features such as deep-packet inspection and firewall
anomaly detection when available to protect embedded and IoT devices.
Ensure secure defaults are adopted and disable unused features and services
on your embedded devices.
Regularly update firmware to the vendor provided latest stable version to
ensure your device is up to date.




Solution

FNET users update to Version 4.7.0 or later   
uIP-Contiki-NG users update to the latest version available at   
open-iscsi users update to the latest version available at   
Maintainers of Nut/Net can update the latest version available at   

Vendor Information

uIP
PicoTCP
FNET
Nut/OS
iscsi
- -8rgp
Microchip
nerability-response/amnesia-network-stack-vulnerability

References

NJCCIC
ous-opensource-tcpip-stacks

US CERT

SIEMENS

FEIG
8-01_SecurityAdvisory.pdf

forescout

IoTSecurityFoundation

CVE Name
CVE-2020-13984
CVE-2020-13985
CVE-2020-13986
CVE-2020-13987
CVE-2020-13988
CVE-2020-17437
CVE-2020-17438
CVE-2020-17439
CVE-2020-17440
CVE-2020-17441
CVE-2020-17442
CVE-2020-17443
CVE-2020-17444
CVE-2020-17445
CVE-2020-17467
CVE-2020-17468
CVE-2020-17469
CVE-2020-17470
CVE-2020-24334
CVE-2020-24335
CVE-2020-24336
CVE-2020-24337
CVE-2020-24338
CVE-2020-24339
CVE-2020-24340
CVE-2020-24383
CVE-2020-25107
CVE-2020-25108
CVE-2020-25109
CVE-2020-25110
CVE-2020-25111
CVE-2020-25112
Severity Rating: HIGH

Software Affected

Contact Form 7 5.3.1 and older versions
Overview

A vulnerability has been discovered in Contact Form 7 version 5.3.1 or
older that allows an attacker to upload malicious scripts.

Description

An unrestricted file upload vulnerability is found in a Word Press plug-in.
 An attacker can exploit this vulnerability to upload arbitrary code and
run it in the context of the web server process. This may facilitate
unauthorized access or privilege escalation. It allows an unauthenticated
user to bypass any form file-type restrictions in Contact Form 7 and upload
an executable binary to a site running the plug-in version 5.3.1 or
earlier. 

Successful exploitation of this vulnerability could allow the attacker to
bypass any form file-type restrictions in Contact Form 7.

Solution

Update to Contact Form 7 5.3.2 


Vendor Information

Word Press

References

Acunetix
7-arbitrary-file-upload-3-5-2/

Searchenginejournal
on-sites/391111/

Threatpost

Security newspaper
wordpress-sites-affected-by-critical-vulnerability/

Tenable

CVE Name
CVE-2020-35489

Severity Rating: HIGH

Software Affected

Foxit Reader versions 10.1.0.37527 and earlier
Foxit Phantom PDF versions 10.1.0.37527 and earlier
Overview

Multiple vulnerabilities have been reported in Foxit Reader and Phantom PDF
which could allow a remote attacker to cause Out-of-Bounds Write Remote
Code Execution, Type Confusion Memory Corruption, denial of service
condition or execute arbitrary code on the target system.

Description

These vulnerabilities exist due to insufficient validation of objects,
incorrect processing of PDF files, lack of proper validation when an
incorrect argument is passed to the app.media.openPlayer function, access
or use of a deleted pointer and array overflow issue. A remote attacker
could exploit these vulnerabilities by sending specially crafted malicious
file on the target system. 

Successful exploitation of these vulnerabilities could allow the attacker
to cause Out-of-Bounds Write Remote Code Execution, Type Confusion Memory
Corruption, denial of service condition or execute arbitrary code on the
target system.

Solution

Upgrade to the Foxit Reader 10.1.1 and Foxit Phantom PDF 10.1.1 


Vendor Information

Foxit Software

References

Foxit Software

CyberSecurityHelp

CVE Name
CVE-2020-27860
CVE-2020-13547
CVE-2020-13548
CVE-2020-13557
CVE-2020-13560
CVE-2020-13570
CVE-2020-28203

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top