CISA Publishes Analysis on New ‘FiveHands’ Ransomware

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2021-22675
PUBLISHED: 2021-05-07

The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, C…

CVE-2021-22679
PUBLISHED: 2021-05-07

The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK v…

CVE-2020-14009
PUBLISHED: 2021-05-07

Proofpoint Enterprise Protection (PPS/PoD) before 8.17.0 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipar…

CVE-2021-21984
PUBLISHED: 2021-05-07

VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Business for Cloud Virtual Appliance.

CVE-2021-26122
PUBLISHED: 2021-05-07

LivingLogic XIST4C before 0.107.8 allows XSS via feedback.htm or feedback.wihtm.

Read More HERE

Leave a Reply