Tag: cvss
-
Walking the Walk: How Tenable Embraces Its >>Secure by Design<< Pledge to CISA
Tags: access, application-security, attack, authentication, best-practice, business, cisa, cloud, conference, container, control, credentials, cve, cvss, cyber, cybersecurity, data, data-breach, defense, exploit, Hardware, identity, infrastructure, injection, Internet, leak, lessons-learned, mfa, open-source, passkey, password, phishing, risk, saas, service, siem, software, sql, strategy, supply-chain, theft, threat, tool, update, vulnerability, vulnerability-managementAs a cybersecurity leader, Tenable was proud to be one of the original signatories of CISA’s “Secure by Design” pledge earlier this year. Our embrace of this pledge underscores our commitment to security-first principles and reaffirms our dedication to shipping robust, secure products that our users can trust. Read on to learn how we’re standing…
-
Veritas Enterprise Vault Vulnerabilities Lets Attackers Execute Arbitrary Code Remotely
Critical security vulnerability has been identified in Veritas Enterprise Vault, a widely-used archiving and content management solution. The vulnerability, rated with a CVSS v3.1 Base Score of 9.8 (Critical), could allow attackers to execute arbitrary code on affected servers. This exploit leverages vulnerabilities inherent to the .NET Remoting service used by Enterprise Vault. The Nature…
-
GeoVision 0-Day Vulnerability Exploited in the Wild
Tags: authentication, cve, cvss, cyber, cybersecurity, exploit, flaw, injection, vulnerability, zero-dayCybersecurity researchers have detected the active exploitation of a zero-day vulnerability in GeoVision devices, which the manufacturer no longer supports. The vulnerability, now designated as CVE-2024-11120, has been assigned a high-severity CVSS score of 9.8 and used by a sophisticated botnet. The security flaw is a pre-authentication command injection vulnerability, which allows attackers to execute arbitrary…
-
High-Severity Flaw in PostgreSQL Allows Hackers to Exploit Environment Variables
Cybersecurity researchers have disclosed a high-severity security flaw in the PostgreSQL open-source database system that could allow unprivileged users to alter environment variables, and potentially lead to code execution or information disclosure.The vulnerability, tracked as CVE-2024-10979, carries a CVSS score of 8.8.Environment variables are user-defined values that can allow a program First seen on thehackernews.com…
-
Thousands of EOL D-Link Routers Vulnerable to Password Change Attacks
In a critical security disclosure, it has been revealed that thousands of end-of-life (EOL) D-Link DSL-6740C routers are vulnerable to password change attacks. The vulnerability tracked as CVE-2024-11068 has been rated as critical by the TWCERT/CC, with an alarming CVSS score of 9.8. The affected routers, no longer supported by D-Link as of January 15, 2024, are…
-
Critical Veeam CVE targeted by new ransomware variant
Multiple ransomware variants are now targeting the CVE, which has a CVSS of 9.8. For customers, the risk of exploitation is only increasing. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/veeam-cve-exploit-frag-ransomware/732670/
-
Understand CVE vs CVSS for Improved Cybersecurity
CWEs and CVEs have similarities and differences. Understanding both can help you keep your organization secure. Staying ahead of vulnerabilities is critical for any cybersecurity pro tasked with protecting an organization’s assets and data in a constantly shifting threat landscape. The Common Vulnerabilities and Exposures (CVE) system and the Common Vulnerability Scoring System (CVSS) are……
-
Max-Critical Cisco Bug Enables Command-Injection Attacks
Though Cisco reports of no known malicious exploitation attempts, but thanks to a CVSS 10 out of 10 security vulnerability (CVE-2024-20418) three of its wireless access points are vulnerable to remote, unauthenticated cyberattacks. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cisco-bug-command-injection-attacks
-
CVSS 9.8 für ScienceLogic SL1 Day-Schwachstelle in ScienceLogic-Monitoring
First seen on security-insider.de Jump to article: www.security-insider.de/-rackspace-warnung-sciencelogic-schwachstelle-update-a-f4569fd7f0bd9e251be849563276c808/
-
Cisco scores a perfect CVSS 10 with critical flaw in its wireless system
Ultra-Reliable Wireless Backhaul doesn’t live up to its name First seen on theregister.com Jump to article: www.theregister.com/2024/11/07/cisco_uiws_flaw/
-
Critical Veeam CVE actively exploited in ransomware attacks
Multiple ransomware groups targeted the vulnerability, which has a CVSS score of 9.8, more than a month after it was disclosed and patched by the data… First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/veeam-critical-cve-exploits-ransomware/730570/
-
CVSS 9.8 für SAP BusinessObjects BI – Deshalb sollten Sie das Oktober-Update von SAP schnellstmöglich installieren
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sicherheitsluecken-sap-business-objects-bi-a-a78a921f070e867a281fcdb41b9f8a0d/
-
The Sky is Falling! (Again)
We’ve been here before, haven’t we? Every other week, a new vulnerability with a sky-high CVSS score causes a frenzy. This time, it’s a 9.9 CVSS vulne… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/10/the-sky-is-falling-again/
-
EPSS vs. CVSS: What’s the Best Approach to Vulnerability Prioritization?
Many businesses rely on the Common Vulnerability Scoring System (CVSS) to assess the severity of vulnerabilities for prioritization. While these score… First seen on thehackernews.com Jump to article: thehackernews.com/2024/09/epss-vs-cvss-whats-best-approach-to.html
-
Kritische Schwachstelle – CVSS 10 Gravierende Sicherheitslücke in GitLab-Server
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sicherheitsluecke-gitlab-aktualisierung-empfohlen-a-8b5682238205777cca84488338d6b379/
-
Critical Nvidia Security Flaw Exposes Cloud AI Systems to Host Takeover
Nvidia confirms risk of code execution, denial of service, escalation of privileges, information disclosure, and data tampering. CVSS 9/10. The post C… First seen on securityweek.com Jump to article: www.securityweek.com/critical-nvidia-container-flaw-exposes-cloud-ai-systems-to-host-takeover/
-
Critical Nvidia Container Flaw Exposes Cloud AI Systems to Host Takeover
Nvidia confirms risk of code execution, denial of service, escalation of privileges, information disclosure, and data tampering. CVSS 9/10. The post C… First seen on securityweek.com Jump to article: www.securityweek.com/critical-nvidia-container-flaw-exposes-cloud-ai-systems-to-host-takeover/
-
CVE-2024-20439 und CVE-2024-20440 – CVSS 9.8 Schwachstelle im Cisco Smart Licensing Utility
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-sicherheitswarnung-kritische-schwachstellen-smart-licensing-utility-a-0940d0adb0d80e8b71058a45a7f8b73d/
-
CVSS 9.9 und 9.1 – Kritische Schwachstellen in Kibana ermöglichen Malware-Angriffe
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sicherheitsluecken-in-kibana-updates-verfuegbar-a-8bffa8d000328fd2825053e9435fe78e/
-
VMware Patches Remote Code Execution Flaw Found in Chinese Hacking Contest
VMware warned that an attacker with network access could send a specially crafted packet to execute remote code. CVSS severity score 9.8/10. The post … First seen on securityweek.com Jump to article: www.securityweek.com/vmware-patches-remote-code-execution-flaw-found-in-chinese-hacking-contest/
-
Kritische Schwachstelle CVE-2024-40766 – CVSS 9.3 Firewalls von Sonicwall in Gefahr
First seen on security-insider.de Jump to article: www.security-insider.de/sonicwall-firewalls-angriffe-schutzmassnahmen-cve-2024-40766-a-fb6be1e1993f9f52f8ca402442ac8faf/
-
Microsoft Patchday September 2024 – CVSS 9.8 Ungewöhnlich viele Schwachstellen unter Angriff
First seen on security-insider.de Jump to article: www.security-insider.de/microsoft-patchday-september-2024-sicherheitsluecken-geschlossen-a-a8e6fbdd0a08424d9e5649faad84faee/
-
Kritische Sicherheitslücken – CVSS 10 und CVSS 9.8 in Windows und WordPress
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sicherheitsluecken-wordpress-windows-a-ac1646154eca9f5f51ca7cbafa79e43e/
-
China-Nexus Group Velvet Ant Exploits Cisco Zero-Day (CVE-2024-20399)
At the beginning of 2024, the Chinese group Velvet Ant exploited a patched zero-day vulnerability (CVE-2024-20399, CVSS 6.7) in Cisco switches to gain… First seen on securityonline.info Jump to article: securityonline.info/china-nexus-group-velvet-ant-exploits-cisco-zero-day-cve-2024-20399/
-
Schwachstellen in AIX mit CVSS von 8.8 – Angreifer können Malware in AIX ausführen
First seen on security-insider.de Jump to article: www.security-insider.de/ibm-aix-sicherheitsupdates-cve-2023-45803-cve-2024-6345-a-bd357378173eebe713e26a72754d0509/
-
Beyond CVSS: Advanced Vulnerability Prioritization Strategies for Modern Threats
The sheer volume of vulnerabilities discovered each year, combined with limited time and resources, demands a more sophisticated strategy for prioriti… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/beyond-cvss-advanced-vulnerability-prioritization-strategies-for-modern-threats/
-
Malware-Gefahr für Kibana – CVSS-9.9-Schwachstelle in Kibana
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-schwachstelle-kibana-sicherheitsupdates-a-fd1bb969e3e4d815126aba466c5dab87/
-
Critical Apache OfBiz Vulnerability Allows Preauth RCE
The enterprise resource planning platform bug CVE-2024-38856 has a vulnerability-severity score of 9.8 out of 10 on the CVSS scale and offers a wide a… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/critical-apache-ofbiz-vulnerability-allows-preauth-rce
-
Sicherheitslücken in Telerik Report Server – CVSS 9.9: Telerik Report Server anfällig für Malware
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sicherheitsluecke-cve-2024-6327-progress-telerik-report-server-a-369ea31e83ec49df65d6a168a59551ae/

