A improper neutralization of special elements used in an os command (‘os command injection’) in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version 2.2.0, FortiIsolator version 2.3.0 through 2.3.4 allows attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters.
Monthly Archives: October 2023
Read Time:25 Second
CVE-2020-27636
CVE-2020-27635
CVE-2020-27634
CVE-2020-27633
CVE-2020-27631
CVE-2020-27630
CVE-2020-27213
Read Time:28 Second
An issue was discovered in Ethernut Nut/OS 5.1. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. While the ISN generator seems to adhere to RFC 793 (where a global 32-bit counter is incremented roughly every 4 microseconds), proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.
IZ1H9 Botnet Targets IoT Devices With New Exploits
Read Time:3 Second
FortiGuard Labs said the new campaign incorporates 13 distinct payloads
Flagstar Bank MOVEit Breach Affects 800K Customer Records
Read Time:5 Second
The incident occurred between May 27 and 31 2023, before MOVEit Transfer vulnerability was publicly disclosed