Fabriquants

Retour à Sécurité

Fortinet

Aruba

    • WPA3 Multiple Vulnerabilities 16 avril 2019

      On April 10, 2019 a research paper by Mathy Vanhoef and Eyal Ronen was released documenting a series of potential vulnerabilities in implementations of WPA3 and EAP-pwd (RFC 5931). Details on EAP-pwd vulnerabilities have not yet been released. This advisory covers only WPA3 vulnerabilities.

    • Aruba Instant Multiple Vulnerabilities 27 février 2019

      Aruba has released updates to Aruba Instant (IAP) that address multiple serious vulnerabilities. The most significant vulnerability is rated CRITICAL with a CVSS score of 9.8.

    • Aruba BLE Radio Firmware Vulnerability 18 octobre 2018
      A vulnerability exists in the firmware of embedded BLE radios that are part of all Aruba AP-3xx series access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP’s BLE radio and could then gain access to the AP’s console port. Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986 …

    • Apache Struts Vulnerability in ClearPass Policy Manager 24 août 2018

      The Apache Struts group announced Struts version 2.3.35 on August 22, 2018.
      Included in this update is a fix for one security vulnerability. Aruba ClearPass includes Apache Struts 2.3.34, but in a non-vulnerable configuration.

    • Linux Kernel Vulnerabilities in ClearPass and AirWave 24 août 2018

      Two Linux kernel vulnerabilities, known as “SegmentSmack” and “FragmentSmack”, have been publicly disclosed. The Linux kernel used by Aruba ClearPass Policy Manager and Aruba AirWave is affected. Other Aruba products are not affected.

    • Return Of Bleichenbacher’s Oracle Threat (ROBOT) 28 mars 2018

      The cryptography library used by Aruba Instant provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker may be able to recover private keys for X.509 certificates. This vulnerability is
      referred to as “ROBOT.”

Cisco

    • Cisco Firepower Detection Engine Secure Sockets Layer Denial of Service Vulnerability 18 avril 2018
      A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device, which could cause a denial of service (DoS) condition. The vulnerability is due to the affected software imp …

    • Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability 18 octobre 2019
      A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploit this vulnerability by submitting malicious HTTP r …

    • Cisco Firepower Management Center Remote Code Execution Vulnerability 18 octobre 2019
      A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary commands with …

    • Cisco Aironet Access Points and Catalyst 9100 Access Points CAPWAP Denial of Service Vulnerability 16 octobre 2019
      A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to improper resource management during CAPWAP message p …

    • Cisco Wireless LAN Controller Secure Shell Denial of Service Vulnerability 16 octobre 2019
      A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the SSH process is not properly deleted when an SSH connection to the device is disconnected. An attacker could exploit this vulnerabili …

    • Cisco Wireless LAN Controller Path Traversal Vulnerability 16 octobre 2019
      A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path …

    • Cisco Expressway Series and TelePresence Video Communication Server Cross-Site Scripting Vulnerability 16 octobre 2019
      A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the …

Google Online Security Blog