Tag : Vulnerabilities

image_pdfimage_print

Vulnerabilities identified in PrinterLogic’s enterprise management printer solution could expose organizations to authentication bypass, SQL injection, cross-site scripting (XSS) and other types of attacks. PrinterLogic’s platform allows organizations to manage all printers within their environments from a single console. An analysis of the PrinterLogic SaaS platform and of the source code of the Virtual Appliance ..

Leggi tutto

A Mirai botnet variant has been exploiting a recently patched vulnerability tracked as CVE-2023-28771 to hack many Zyxel firewalls.  The Taiwan-based networking device manufacturer informed customers about the security hole on April 25, when it announced the availability of patches for impacted ATP, VPN, USG Flex and ZyWALL/USG firewalls. The OS command injection vulnerability, found ..

Leggi tutto

DevOps platform GitLab this week resolved a critical-severity vulnerability impacting both GitLab Community Edition (CE) and Enterprise Edition (EE). An open source end-to-end software development platform, GitLab helps developers and organizations build, secure, and operate software. The platform has approximately 30 million registered users. Tracked as CVE-2023-2825 and leading to arbitrary file reads, the newly ..

Leggi tutto

Security, application delivery and data protection solutions provider Barracuda Networks is warning customers about a zero-day vulnerability that has been exploited to hack the company’s  Email Security Gateway (ESG) appliances. The zero-day, tracked as CVE-2023-2868, was addressed with a patch (BNSF-36456) that has been automatically applied to all impacted appliances. An entry in NIST’s vulnerability ..

Leggi tutto

Latvian network equipment manufacturer MikroTik has shipped a patch for a major security defect in its RouterOS product and confirmed the vulnerability was exploited five months ago at the Pwn2Own Toronto hacking contest. In a barebones advisory documenting the CVE-2023-32154 flaw, Mikrotik confirmed the issue affects devices running MikroTik RouterOS versions v6.xx and v7.xx with ..

Leggi tutto

Security researchers are warning that vulnerabilities patched in the open-source Pimcore platform could have led to the execution of arbitrary code when clicking on a link. A digital experience platform, Pimcore provides data and user experience management capabilities to over 100,000 organizations worldwide. In March 2023, version 10.5.19 of the Pimcore platform resolved two issues ..

Leggi tutto

Apple on Thursday released security updates for its operating systems to patch dozens of vulnerabilities that could expose iPhones and Macs to hacker attacks, including three zero-days affecting the WebKit browser engine. Two of the actively exploited vulnerabilities, CVE-2023-28204 and CVE-2023-32373, have been reported to the tech giant by an anonymous researcher. Their exploitation can ..

Leggi tutto

Google on Wednesday announced that it’s updating the Android and Google Devices Vulnerability Reward Program (VRP) with a new system for rating the quality of bug reports. The new quality rating system, the internet giant says, should encourage researchers to provide more details on the identified security defects and should also help address them faster. ..

Leggi tutto