CURRENT ACTIVITIES 
Threat actors exploiting authentication bypass vulnerability in Fortinet Products
Indian - Computer Emergency Response Team (cert-in.org.in)


It is reported that threat actors are actively exploiting an authentication bypass vulnerability in Fortinet Products. The vulnerability allows the attacker to gain access to administrative interface and perform actions via a specially crafted request.

Software Affected

Forti OS versions 7.0.0 to 7.0.6 and 7.2.0 to 7.2.1
Forti Proxy versions 7.0.0 to 7.0.6 and 7.2.0
Forti Switch Manager versions 7.2.0 and 7.0.0
Description

This vulnerability exists in FortiOS, FortiProxy and FortiSwitchManager due to an authentication error. An attacker could exploit this vulnerability by sending a specially crafted HTTP/HTTPS request to the target user and adding a SSH key to the admin user. The attacker gains access to the SSH into the affected system as admin.

Successful exploitation of this vulnerability could allow the attacker to bypass security restrictions and gain complete access to the target system.

Note: It is to be noted that this vulnerability is being exploited in the Wild in case the patches are not updated.

Solution

Upgrade to the latest versions of FortiOS, FortiProxy and FortiSwitchManager as mentioned in the vendor advisory:


Vendor Information

Fortiguard

Reference


CVE Name
CVE-2022-40684

 

Multiple vulnerabilities in Mozilla Products 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Mozilla Firefox versions prior to 107
Mozilla Firefox ESR versions prior to 102.5
Mozilla Thunderbird versions prior to 102.5
Overview

Multiple vulnerabilities have been reported in Mozilla products, which
could allow an attacker to bypass security restrictions, execute arbitrary
code, gain access to potentially sensitive information, perform Cross-Site
Scripting (XSS) attacks, perform spoofing attacks or cause a denial of
service (DoS) condition on the targeted system.

Description

These vulnerabilities exist in Mozilla Products due to cross-origin policy
violations, a flaw in the handling of a series of popups and window.print()
events, Use-after-free in Input Stream implementation, Java Script Realm,
Garbage collection, expat, a use-after-free while loading a font using
FontFace(), an error when handling Same Site cookies, non-standard headers,
a boundary condition when resolving a symlink such as
file:///proc/self/fd/1, insecure handling of downloaded files, Keystroke
Side-Channel Leakage, incorrect detection of private browsing mode by
Service Workers, incorrect processing of custom mouse cursor, improper
handling deletion of a security exception granted for an invalid TLS
certificate, tables inside of an iframe and memory corruption error. A
remote attacker could exploit these vulnerabilities by persuading a victim
to visit a specially-crafted Web site.

Successful exploitation of these vulnerabilities could allow a remote
attacker to bypass security restrictions, execute arbitrary code, gain
access to potentially sensitive information, perform Cross-Site Scripting
(XSS) attacks, perform spoofing attacks or cause a denial of service (DoS)
condition on the targeted system.

Solution

Apply appropriate software updates as mentioned in the Mozilla Security
Advisory:




Vendor Information

Mozilla

References

Mozilla

CVE Name
CVE-2022-45403
CVE-2022-45404
CVE-2022-45405
CVE-2022-45406
CVE-2022-45407
CVE-2022-45408
CVE-2022-45409
CVE-2022-45410
CVE-2022-45411
CVE-2022-45412
CVE-2022-45413
CVE-2022-40674
CVE-2022-45415
CVE-2022-45416
CVE-2022-45417
CVE-2022-45418
CVE-2022-45419
CVE-2022-45420
CVE-2022-45421


 

Denial of Service Vulnerability in RUGGEDCOM ROS V4 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: MEDIUM

Software Affected

RUGGEDCOM ROS i800 V4.X: All versions
RUGGEDCOM ROS i801 V4.X: All versions
RUGGEDCOM ROS i802 V4.X: All versions
RUGGEDCOM ROS i803 V4.X: All versions
RUGGEDCOM ROS RMC30 V4.X: All versions
RUGGEDCOM ROS RMC8388 V4.X: All versions
RUGGEDCOM ROS RP110 V4.X: All versions
RUGGEDCOM ROS RS400 V4.X: All versions
RUGGEDCOM ROS RS401 V4.X: All versions
RUGGEDCOM ROS RS416Pv2 V4.X: All versions
RUGGEDCOM ROS RS416v2 V4.X: All versions
RUGGEDCOM ROS RS900 (32M) V4.X: All versions
RUGGEDCOM ROS RS900 V4.X: All versions
RUGGEDCOM ROS RS900G (32M) V4.X: All versions
RUGGEDCOM ROS RS900G V4.X: All versions
RUGGEDCOM ROS RS900GP V4.X: All versions
RUGGEDCOM ROS RS900L V4.X: All versions
RUGGEDCOM ROS RS900M V4.X: All versions
RUGGEDCOM ROS RS900W V4.X: All versions
RUGGEDCOM ROS RS910 V4.X: All versions
RUGGEDCOM ROS RS910L V4.X: All versions
RUGGEDCOM ROS RS910W V4.X: All versions
RUGGEDCOM ROS RS920L V4.X: All versions
RUGGEDCOM ROS RS920W V4.X: All versions
RUGGEDCOM ROS RS930L V4.X: All versions
RUGGEDCOM ROS RS930W V4.X: All versions
RUGGEDCOM ROS RS940G V4.X: All versions
RUGGEDCOM ROS RS1600 V4.X: All versions
RUGGEDCOM ROS RS1600F V4.X: All versions
RUGGEDCOM ROS RS1600T V4.X: All versions
RUGGEDCOM ROS RS8000 V4.X: All versions
RUGGEDCOM ROS RS8000A V4.X: All versions
RUGGEDCOM ROS RS8000H V4.X: All versions
RUGGEDCOM ROS RS8000T V4.X: All versions
RUGGEDCOM ROS RSG920P V4.X: All versions
RUGGEDCOM ROS RSG2100 (32M) V4.X: All versions
RUGGEDCOM ROS RSG2100 V4.X: All versions
RUGGEDCOM ROS RSG2100P V4.X: All versions
RUGGEDCOM ROS RSG2200 V4.X: All versions
RUGGEDCOM ROS RSG2288 V4.X: All versions
RUGGEDCOM ROS RSG2300 V4.X: All versions
RUGGEDCOM ROS RSG2300P V4.X: All versions
RUGGEDCOM ROS RSG2488 V4.X: All versions
Overview

A vulnerability has been reported in Siemen products which could allow a
remote attacker to cause a Denial-of-service condition (slowloris) on the
targeted system.

Description

This vulnerability exists in Siemen products due to improper input
validation in the RUGGEDCOM ROS-based V4 devices. A remote attacker could
exploit this vulnerability by sending a crafted HTTP request to the web
interface of an affected device.

Successful exploitation of this vulnerability could allow a remote attacker
to cause a Denial-of-service condition (slowloris) on the targeted system.

Workaround

The user may apply the following workaround to reduce the risk, as provided
by the vendor.

Restrict access to port 80/tcp and 443/tcp to trusted IP addresses only.
Deactivate the webserver if not required, and if deactivation is supported
by the product.
Vendor Information

SIEMENS

References

SIEMENS

CVE Name
CVE-2022-39158


 

Command injection vulnerability in IBM InfoSphere Information Server 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

IBM InfoSphere Information Server version 11.7
Overview

A vulnerability has been reported in IBM InfoSphere Information Server
which could allow a remote attacker to execute arbitrary OS commands on the
targeted system.

Description

This vulnerability exists in IBM InfoSphere Information Server due to
improper input validation of special elements . A remote attacker could
exploit this vulnerability by sending specially crafted data to the
application.

Successful exploitation of this vulnerability could allow a remote attacker
to execute arbitrary OS commands on the targeted system.

Solution

Apply appropriate software fixes as available on the vendor website:


Vendor Information

IBM

CVE Name
CVE-2022-40752


 

Multiple Vulnerabilities in IBM WebSphere Application Server 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: MEDIUM

Software Affected

IBM WebSphere Application Server version 9.0
IBM WebSphere Application Server version 8.5
IBM WebSphere Application Server Liberty Continuous delivery
Overview

Multiple vulnerabilities have been reported in IBM WebSphere Application
Server and IBM Application Server Liberty which could be exploited by
unauthenticated remote attacker to manipulate data or cause denial of
service condition (DoS) condition on the targeted system.

Description

1. Data Manipulation Vulnerability ( CVE-2022-21624   )

This vulnerability exists in Java SE due to improper input validation
within the JNDI component in Oracle GraalVM Enterprise Edition. An
unauthenticated remote attacker could exploit this vulnerability to
manipulate data on the targeted system.

2. Denial of Service Vulnerability ( CVE-2022-21626   )

This vulnerability exists in Java SE due to improper input validation
within the Security component in Oracle GraalVM Enterprise Edition. An
unauthenticated remote attacker could exploit this vulnerability to perform
denial of service (DoS) condition on the targeted system.

Solution

Apply appropriate patches as mentioned in IBM Security Bulletin


Vendor Information

IBM

References

IBM

CVE Name
CVE-2022-21624
CVE-2022-21626


 

Multiple Vulnerabilities in Trend Micro Apex One 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Trend Micro Apex One - 2019 (On-prem)
Trend Micro Apex One as a Service (SaaS)
Overview

Multiple vulnerabilities have been reported in Trend Micro Apex One, which could allow an attacker to access sensitive information, gain elevated privileges or bypass security restrictions on the targeted system.

Description

1. Information Disclosure Vulnerabilities ( CVE-2022-44647   CVE-2022-44648   )

These vulnerabilities exist in Trend Micro Apex One and Apex One as a Service due to an out-of-bounds read error. Successful exploitation of these vulnerabilities could allow a local attacker to disclose sensitive information of the targeted system.

2. Privilege Escalation Vulnerabilities ( CVE-2022-44649   CVE-2022-44650   CVE-2022-44651   CVE-2022-44652   CVE-2022-44653   )

These vulnerabilities exist in Trend Micro Apex One and Apex One as a Service due to an out-of-bounds access error, memory corruption error in the Unauthorized Change Prevention service, a Time-of-Check Time-Of-Use error, improper handling of exceptional conditions, or directory traversal error. Successful exploitation of these vulnerabilities could allow a local attacker to gain escalated privileges on the targeted system.

3. Security Bypass Vulnerability ( CVE-2022-44654   )

This vulnerability exists in the monitor engine component of Trend Micro Apex One and Apex One as a Service which is complied without the /SAFESEH memory protection mechanism. An attacker could exploit this vulnerability by sending malicious payloads to the affected system. Successful exploitation of this vulnerability could allow the attacker to bypass security restrictions on the targeted system.

Solution

Apply appropriate updates as mentioned by the vendor:


Vendor Information

Trend Micro

References

Trend Micro

CVE Name
CVE-2022-44647
CVE-2022-44648
CVE-2022-44649
CVE-2022-44650
CVE-2022-44651
CVE-2022-44652
CVE-2022-44653
CVE-2022-44654

 

Multiple Vulnerabilities in Google ChromeOS 
Indian - Computer Emergency Response Team (cert-in.org.in)

Severity Rating: HIGH

Software Affected

Google ChromeOS Stable channel versions prior to 108.0.5359.71 for Mac and Linux
Google ChromeOS Stable channel versions prior to 108.0.5359.71/72 for Windows
Overview

Multiple vulnerabilities have been reported in Google Chrome OS which could be exploited by a remote attacker to bypass security restrictions, execute arbitrary code or cause denial of service condition on the targeted system.

Description

Multiple vulnerabilities exist in Google Chrome OS due to type confusion in V8; Use after free in Camera Capture, Extensions, Mojo, Audio, Forms, Sign-In, Live Caption and Accessibility;  Out-of bounds write in Lacros Graphics; Inappropriate implementation in Fenced Frames and Navigation; Insufficient policy enforcement in Popup Blocker, Autofill, DevTools, File System API and Safe Browsing; Insufficient validation of untrusted input in Downloads and CORS; Insufficient data validation in Directory. An attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web site.

Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restriction, execute arbitrary code or cause denial of service condition on the targeted system.

Solution

Apply appropriate updates as mentioned


Vendor Information

Google Chrome

References

Google Chrome

CVE Name
CVE-2022-4174
CVE-2022-4175
CVE-2022-4176
CVE-2022-4177
CVE-2022-4178
CVE-2022-4179
CVE-2022-4180
CVE-2022-4181
CVE-2022-4182
CVE-2022-4183
CVE-2022-4184
CVE-2022-4185
CVE-2022-4186
CVE-2022-4187
CVE-2022-4188
CVE-2022-4189
CVE-2022-4190
CVE-2022-4191
CVE-2022-4192
CVE-2022-4193
CVE-2022-4194
CVE-2022-4195

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top