Autore: Angelo Barbosa

CVE-2023-37926 | Zyxel ATP/USG FLEX/USG FLEX 50/USG20-VPN/VPN CLI Command buffer overflow

A vulnerability classified as critical has been found in Zyxel ATP, USG FLEX, USG FLEX 50, USG20-VPN and VPN. This affects an unknown part of the component CLI Command Handler. The manipulation leads to buffer overflow. This vulnerability is uniquely identified as CVE-2023-37926. An attack has to be approached locally. There is no exploit...

Per saperne di più

CVE-2023-5797 | Zyxel ATP Debug CLI Command privileges management

A vulnerability was found in Zyxel ATP, USG FLEX, USG FLEX 50, USG20-VPN, VPN, NWA50AX, WAC500, WAX300H and WBE660S. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Debug CLI Command Handler. The manipulation leads to improper privilege management. This vulnerability is known as CVE-2023-5797. It is possible to launch the attack on the local host. There is no exploit...

Per saperne di più

CVE-2023-48713 | knative serving up to 0.38.x Autoscaler /metrics resource consumption (GHSA-qmvj-4qr9-v547)

A vulnerability was found in knative serving up to 0.38.x. It has been classified as problematic. Affected is an unknown function of the file /metrics of the component Autoscaler. The manipulation leads to resource consumption. This vulnerability is traded as CVE-2023-48713. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-49075 | Pimcore admin-ui-classic-bundle up to 1.2.1 single-factor authentication (GHSA-9wwg-r3c7-4vfg)

A vulnerability was found in Pimcore admin-ui-classic-bundle up to 1.2.1 and classified as critical. This issue affects some unknown processing. The manipulation leads to use of single-factor authentication. The identification of this vulnerability is CVE-2023-49075. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più