Vulnerability Summary for the Week of September 14, 2020

Original release date: September 21, 2020  High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info apache -- struts Apache Struts 2.0.0 to 2.5.20 forced double…

Comments Off on Vulnerability Summary for the Week of September 14, 2020

Samba Releases Security Update for CVE-2020-1472

Original release date: September 21, 2020The Samba Team has released a security update to address a critical vulnerability—CVE-2020-1472—in multiple versions of Samba. This vulnerability could allow a remote attacker to…

Comments Off on Samba Releases Security Update for CVE-2020-1472

CISA Releases Emergency Directive on Microsoft Windows Netlogon Remote Protocol

Original release date: September 18, 2020The Cybersecurity and Infrastructure Security Agency (CISA) has released Emergency Directive (ED) 20-04 addressing a critical vulnerability— CVE-2020-1472—affecting Microsoft Windows Netlogon Remote Protocol. An unauthenticated…

Comments Off on CISA Releases Emergency Directive on Microsoft Windows Netlogon Remote Protocol

CERT/CC Releases Information on Critical Vulnerability in Microsoft Windows Netlogon Remote Protocol

Original release date: September 17, 2020The CERT Coordination Center (CERT/CC) has released information on CVE-2020-1472, a vulnerability affecting Microsoft Windows Netlogon Remote Protocol. An unauthenticated attacker could exploit this vulnerability…

Comments Off on CERT/CC Releases Information on Critical Vulnerability in Microsoft Windows Netlogon Remote Protocol

Adobe Releases Security Update for Media Encoder

Original release date: September 16, 2020Adobe has released a security update to address vulnerabilities in Media Encoder. An attacker could exploit these vulnerabilities to obtain sensitive information. The Cybersecurity and…

Comments Off on Adobe Releases Security Update for Media Encoder

AA20-259A: Iran-Based Threat Actor Exploits VPN Vulnerabilities

Original release date: September 15, 2020SummaryThis Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise framework for all referenced threat actor techniques.…

Comments Off on AA20-259A: Iran-Based Threat Actor Exploits VPN Vulnerabilities

AR20-259A: MAR-10297887-1.v1 – Iranian Web Shells

Original release date: September 15, 2020Description Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any…

Comments Off on AR20-259A: MAR-10297887-1.v1 – Iranian Web Shells

Iran-Based Threat Actor Exploits VPN Vulnerabilities

Original release date: September 15, 2020The Cybersecurity Security and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have released a Joint Cybersecurity Advisory on an Iran-based malicious…

Comments Off on Iran-Based Threat Actor Exploits VPN Vulnerabilities

Vulnerability Summary for the Week of September 7, 2020

Original release date: September 14, 2020  High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info cisco -- fxos A vulnerability in Cisco FXOS Software could…

Comments Off on Vulnerability Summary for the Week of September 7, 2020

Exploit for Netlogon Remote Protocol Vulnerability, CVE-2020-1472

Original release date: September 14, 2020The Cybersecurity and Infrastructure Security Agency (CISA) is aware of publicly available exploit code for CVE-2020-1472, an elevation of privilege vulnerability in Microsoft’s Netlogon. Although…

Comments Off on Exploit for Netlogon Remote Protocol Vulnerability, CVE-2020-1472