Original release date: April 6, 2020
The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available.
High Vulnerabilities
Primary Vendor — Product |
Description | Published | CVSS Score | Source & Patch Info |
---|---|---|---|---|
accenture — mercury |
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. | 2020-03-27 | 7.5 | CVE-2020-10990 MISC MISC |
alienform2 — alienform2 |
Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exploit this via a series of crafted requests. | 2020-04-01 | 10 | CVE-2020-10948 MISC |
apache — http_server |
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. | 2020-04-01 | 7.5 | CVE-2020-1934 CONFIRM MLIST MLIST |
apple — macos_catalina |
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.4. An application may be able to execute arbitrary code with system privileges. | 2020-04-01 | 9.3 | CVE-2020-3903 MISC |
apple — macos_catalina |
Multiple issues were addressed by updating to version 8.1.1850. This issue is fixed in macOS Catalina 10.15.4. Multiple issues in Vim. | 2020-04-01 | 7.5 | CVE-2020-9769 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to leak memory. | 2020-04-01 | 10 | CVE-2020-3847 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges. | 2020-04-01 | 9.3 | CVE-2020-3892 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges. | 2020-04-01 | 9.3 | CVE-2020-3893 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges. | 2020-04-01 | 9.3 | CVE-2020-3904 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. | 2020-04-01 | 7.5 | CVE-2020-3849 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges. | 2020-04-01 | 9.3 | CVE-2020-3905 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. | 2020-04-01 | 7.5 | CVE-2020-3850 MISC |
apple — macos_catalina_and_mojave_and_high_sierra |
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. | 2020-04-01 | 7.5 | CVE-2020-3848 MISC |
apple — multiple_products |
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2. | 2020-04-01 | 7.5 | CVE-2020-3911 MISC MISC MISC MISC MISC MISC MISC |
apple — multiple_products |
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2. | 2020-04-01 | 7.5 | CVE-2020-3910 MISC MISC MISC MISC MISC MISC MISC |
apple — multiple_products |
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2. | 2020-04-01 | 7.5 | CVE-2020-3909 MISC MISC MISC MISC MISC MISC MISC |
apple — multiple_products |
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges. | 2020-04-01 | 9.3 | CVE-2020-9785 MISC MISC MISC MISC |
apple — multiple_products |
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to execute arbitrary code with system privileges. | 2020-04-01 | 9.3 | CVE-2020-9768 MISC MISC MISC |
apple — multiple_products |
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges. | 2020-04-01 | 9.3 | CVE-2020-3919 MISC MISC MISC MISC |
apple — multiple_products |
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to arbitrary code execution. | 2020-04-01 | 9.3 | CVE-2020-3895 MISC MISC MISC MISC MISC MISC MISC |
apple — multiple_products |
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A remote attacker may be able to cause arbitrary code execution. | 2020-04-01 | 9.3 | CVE-2020-3899 MISC MISC MISC MISC MISC MISC |
apple — multiple_products |
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A remote attacker may be able to cause arbitrary code execution. | 2020-04-01 | 9.3 | CVE-2020-3897 MISC MISC MISC MISC MISC MISC MISC |
avast — avast_antivirus |
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled. | 2020-04-01 | 7.5 | CVE-2020-10867 MISC MISC MISC |
azkaban — azkaban |
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. | 2020-03-27 | 7.5 | CVE-2020-10992 MISC |
bubblewrap — bubblewrap |
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap –userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unprivileged user namespaces enabled (not default) This has been fixed in the 0.4.1 release, and all affected users should update. | 2020-03-31 | 8.5 | CVE-2020-5291 MISC CONFIRM |
buildah — buildah |
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user’s system anywhere that the user has permissions. | 2020-03-31 | 9.3 | CVE-2020-10696 MISC CONFIRM MISC |
cacagoo — tv-288zd-2mp_devices |
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required. | 2020-04-02 | 10 | CVE-2020-6852 MISC MISC |
dell — emc_idrac_devices |
Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data. | 2020-03-31 | 10 | CVE-2020-5344 MISC |
effect — effect |
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument. | 2020-04-02 | 7.5 | CVE-2020-7624 MISC MISC |
elastic — elasticsearch |
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges. | 2020-03-31 | 7.5 | CVE-2020-7009 N/A CONFIRM N/A |
f5 — nginx_controller |
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system. | 2020-03-27 | 7.5 | CVE-2020-5863 MISC |
git-add-remote — git-add-remote |
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument. | 2020-04-02 | 7.5 | CVE-2020-7630 MISC MISC |
gitlab — gitlab |
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. | 2020-03-27 | 7.5 | CVE-2020-10956 CONFIRM MISC |
hiproxy — op-broswer |
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function. | 2020-04-02 | 7.5 | CVE-2020-7625 MISC MISC |
ibm — spectrum_protect_plus |
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966. | 2020-03-31 | 9 | CVE-2020-4206 XF CONFIRM |
ibm — spectrum_protect_plus |
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975. | 2020-03-31 | 7.5 | CVE-2020-4208 XF CONFIRM |
ibm — spectrum_protect_plus_and_spectrum_scale |
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418. | 2020-03-31 | 9 | CVE-2020-4241 XF CONFIRM |
ibm — spectrum_protect_plus_and_spectrum_scale |
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419. | 2020-03-31 | 9 | CVE-2020-4242 XF CONFIRM |
install-package — install-package |
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. | 2020-04-02 | 7.5 | CVE-2020-7629 MISC MISC |
install-package — install-package |
install-package through 1.1.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the device function. | 2020-04-02 | 7.5 | CVE-2020-7628 MISC MISC |
karma-mojo — karma-mojo |
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. | 2020-04-02 | 7.5 | CVE-2020-7626 MISC MISC |
ksh — ksh |
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely. | 2020-04-02 | 7.2 | CVE-2019-14868 CONFIRM MISC |
laminar_research — x-plane |
X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or arbitrary code execution. | 2020-03-30 | 7.5 | CVE-2019-19605 MISC |
laminar_research — x-plane |
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system. | 2020-03-30 | 10 | CVE-2019-19606 MISC |
lenovo — multiple_notebooks |
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system. | 2020-03-27 | 10 | CVE-2015-5684 MISC |
lenovo — multiple_products | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could allow a user to execute arbitrary code with elevated privileges. | 2020-03-27 | 7.2 | CVE-2015-7334 MISC |
lenovo — multiple_products |
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a user to execute arbitrary code with elevated privileges. | 2020-03-27 | 7.2 | CVE-2015-7333 MISC |
lenovo — solution_center |
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary code with elevated privileges. | 2020-03-27 | 7.2 | CVE-2015-8534 MISC |
lenovo — solution_center |
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary code with elevated privileges. | 2020-03-27 | 7.2 | CVE-2015-8535 MISC |
march_networks — command_client |
The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects. | 2020-04-01 | 7.5 | CVE-2019-9163 CONFIRM |
mongodb — js-bson |
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object’s _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type. | 2020-03-30 | 7.5 | CVE-2020-7610 MISC |
mulesoft — apikit |
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java | 2020-03-27 | 7.5 | CVE-2020-10991 MISC |
node-key-sender — node-key-sender |
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the ‘arrParams’ argument in the ‘execute()’ function. | 2020-04-02 | 7.5 | CVE-2020-7627 MISC MISC |
objectcomputing — micronaut |
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client. | 2020-03-30 | 7.5 | CVE-2020-7611 MISC MISC MISC |
odata4j — odata4j | odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. | 2020-03-30 | 7.5 | CVE-2016-11024 MISC |
odata4j — odata4j |
odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. | 2020-03-30 | 7.5 | CVE-2016-11023 MISC |
paessler — prtg_network_monitor |
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form. | 2020-03-30 | 7.5 | CVE-2020-10374 MISC CONFIRM |
pam-krb5 — pam-krb5 |
pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library by a single ‘ |