ZDI-24-901: NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability

Read Time:13 Second

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-6814.

Read More

SolarWinds Serv-U Information Disclosure Vulnerability (CVE-2024-28995)

Read Time:54 Second

What is the Vulnerability?A Directory Traversal Vulnerability in SolarWinds Serv-U software is being actively exploited in the wild. Tracked as CVE-2024-28995, the vulnerability is due to improper validation of the user-supplied inputs. An attacker could exploit this vulnerability by sending crafted requests to the target host machine. Successful exploitation could allow access to read sensitive files on the host machine. CISA has added CVE-2024-28995 to its Known Exploited Vulnerabilities (KEV) catalog on July 17, 2024 and a publicly available proof-of-concept (PoC) exploit code is available.What is the recommended Mitigation?Apply the most recent upgrade or patch from the vendor. https://www.solarwinds.com/trust-center/security-advisories/cve-2024-28995 What FortiGuard Coverage is available?FortiGuard Labs has provided protection through the IPS signature ” SolarWinds.Serv-U.InternalDir.Directory.Traversal” to detect and block any attack attempts targeting the vulnerability (CVE-2024-28995).  FortiGuard Endpoint Vulnerability Signature can help to detect vulnerable software instances (CVE-2024-28995).  The FortiGuard Incident Response team can be engaged to help with any suspected compromise.

Read More

Smashing Security podcast #381: Trump shooting conspiracy, Squarespace account hijack, and the butt stops here

Read Time:20 Second

Social media fuels conspiracies galore after Donald Trump is shot at a rally, cryptocurrency websites are hijacked after a screw-up at Squarespace, and our guest takes a close look at bottoms on Instagram.

All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Zoë Rose.

Read More