Vulnerability Summary for the Week of March 30, 2020

Original release date: April 6, 2020The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet…

Comments Off on Vulnerability Summary for the Week of March 30, 2020

MS-ISAC Releases Advisory on DrayTek Devices

The Multi-State Information Sharing & Analysis Center (MS-ISAC) has released an advisory regarding two vulnerable command injection points in DrayTek devices (CVE-2020-8515). An attacker could exploit these vulnerabilities to take…

Comments Off on MS-ISAC Releases Advisory on DrayTek Devices

Microsoft RCE Vulnerabilities Affecting Windows, Windows Server

Microsoft has released a security advisory to address remote code execution vulnerabilities in Adobe Type Manager Library affecting all currently supported versions of Windows and Windows Server operating systems. A…

Comments Off on Microsoft RCE Vulnerabilities Affecting Windows, Windows Server

Cisco Releases Security Updates for SD-WAN Solution Software

Cisco has released security updates to address multiple vulnerabilities in SD-WAN Solution software. An attacker could exploit these vulnerabilities to take control of an affected system. For updates addressing lower…

Comments Off on Cisco Releases Security Updates for SD-WAN Solution Software

VMware Releases Security Updates for Multiple Products

VMware has released security updates to address vulnerabilities in multiple products. An attacker could exploit these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure Security Agency…

Comments Off on VMware Releases Security Updates for Multiple Products

AA20-073A: Enterprise VPN Security

As organizations prepare for possible impacts of Coronavirus Disease 2019 (COVID-19), many may consider alternate workplace options for their employees. Remote work options—or telework—require an enterprise virtual private network (VPN)…

Comments Off on AA20-073A: Enterprise VPN Security