Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net
  • Blog

    Adobe ColdFusion Access Control Bypass

    What is the vulnerability?The Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a security bypass. Exploitation of these vulnerabilities could give attacker access to the ColdFusion Administrator endpoints for further attack.What is the Vendor Solution?Adobe released patches for the security bypass flaws…

    Read More Adobe ColdFusion Access Control BypassContinue

  • Blog

    Apache OFBiz Authentication Bypass

    What is the vulnerability?There is an authentication bypass vulnerability in Apache OFBiz tracked under CVE-2023-51467 and CVE-2023-49070. Successful exploitation would let an attacker circumvent authentication processes, enabling them to remotely execute arbitrary code and access sensitive information. Apache OFBiz is an open-source business application suite for Enterprise Resource Planning (ERP) which integrates and automates many…

    Read More Apache OFBiz Authentication BypassContinue

  • Blog

    Active Exploitation of SolarView Compact Command Injection Vulnerabilities

    What is SolarView Compact?SolarView Compact is a photovoltaic (PV) power generation measurement and monitoring device developed by Contec. What is the Attack?CVE-2022-29303 is a command injection vulnerability in SolarView Compact that allows attackers to steal or modify information, destroy the system, or execute malicious programs by entering commands from the test email transmission screen.CVE-2022-40881 is…

    Read More Active Exploitation of SolarView Compact Command Injection VulnerabilitiesContinue

  • Blog

    ArcaneDoor Attack

    rnWhat is the Attack?rnCisco issued an advisory on 24th April, regarding its Adaptive Security Appliances, multifunctional devices combining firewall, VPN, and other security functions. It reported that these appliances had become the focus of state-sponsored espionage, with attackers exploiting two previously unknown vulnerabilities to infiltrate government entities worldwide. In this campaign, two backdoors were deployed:…

    Read More ArcaneDoor AttackContinue

  • Blog

    Rockwell Automation ControlLogix Communication Modules Vulnerabilities

    Post Content

    Read More Rockwell Automation ControlLogix Communication Modules VulnerabilitiesContinue

  • Blog

    Akira Ransomware Attack

    Post Content

    Read More Akira Ransomware AttackContinue

  • Blog

    Mitel MiCollab Unauthorized Access

    What is the attack?Security flaws in Mitel MiCollab, CVE-2024–35286 and CVE-2024–41713, have been found, putting many organizations at risk. These vulnerabilities allow attackers bypass authentication and access files on affected servers, revealing sensitive information that could expose organizations to serious security risks. Mitel MiCollab is a popular solution that combines voice calling, video calling, chat,…

    Read More Mitel MiCollab Unauthorized AccessContinue

  • Blog

    Cleo Multiple File Transfer Vulnerabilities

    Post Content

    Read More Cleo Multiple File Transfer VulnerabilitiesContinue

  • Blog

    Ivanti Cloud Services Application (CSA) Vulnerabilities

    What are the Vulnerabilities?Ivanti has released security updates to address multiple critical flaws in its Cloud Services Application (CSA) that could lead to privilege escalation and code execution. More details below:CVE-2024-11639, CVSS: 10.0 (Maximum Severity), authentication bypass vulnerability in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain…

    Read More Ivanti Cloud Services Application (CSA) VulnerabilitiesContinue

  • Blog

    Oracle WebLogic Server Vulnerabilities

    What is the attack?A threat actor known as Water Sigbin (aka the 8220 Gang) is seen exploiting two vulnerabilities in the Oracle WebLogic server: CVE-2017-3506, which allows remote OS command execution, and CVE-2023-21839 is an insecure deserialization vulnerability. CISA recently added the Oracle WebLogic flaw tracked as CVE-2017-3506 to its known exploited vulnerabilities catalog on…

    Read More Oracle WebLogic Server VulnerabilitiesContinue

Page navigation

Previous PagePrevious 1 … 292 293 294 295 296 … 489 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us