Tag: cvss
-
Angreifer können Cisco SEG übernehmen – CVSS 9.8 Sicherheitslücke in Cisco Secure Email Gateway
First seen on security-insider.de Jump to article: www.security-insider.de/cisco-secure-email-gateway-schwachstelle-update-a-99be56431542b3cafb1e82ba6df075b4/
-
Cisco schließt kritische Sicherheitslücke in SSM On-Prem – CVSS-10-Schwachstelle in Cisco Smart Software Manager
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sicherheitsluecke-cisco-smart-software-manager-on-prem-a-f3dc3073995eec63a2fae505e0ed2ca5/
-
Docker Patches Critical AuthZ Plugin Bypass Vulnerability Dating Back to 2018
The vulnerability, tagged as CVE-2024-41110 with a CVSS severity score of 10/10, was originally found and fixed in 2018. The post Docker Patches Criti… First seen on securityweek.com Jump to article: www.securityweek.com/docker-patches-critical-authz-plugin-bypass-vulnerability-dating-back-to-2018/
-
Critical Cellopoint Secure Email Gateway Flaw Let Attackers Execute Arbitrary Code
A critical vulnerability has been discovered in the Cellopoint Secure Email Gateway, identified as CVE-2024-6744. This flaw assigned a CVSS score of 9… First seen on gbhackers.com Jump to article: gbhackers.com/cellopoint-secure-email-gateway-flaw/
-
Kritische Sicherheitslücke in Juniper Session Smart Routern – CVSS 10 Schwachstelle in Juniper-Routern
First seen on security-insider.de Jump to article: www.security-insider.de/updates-juniper-sicherheitsluecken-session-smart-router-a-c8a92a27eeee3031e6a83d69aee86420/
-
CVSS Score: A Comprehensive Guide to Vulnerability Scoring
Security professionals constantly battle to identify and patch vulnerabilities before attackers exploit them. But how do we measure the severity of th… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/cvss-score-a-comprehensive-guide-to-vulnerability-scoring/
-
Patched: RCE Flaw That Affects Critical Manufacturing
Hackers Have Not Yet Exploited the CVSS 10-Rated Flaw, Says PTC. Software maker for critical manufacturing organizations PTC patched a critical flaw t… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/patched-rce-flaw-that-affects-critical-manufacturing-a-25699
-
CVSS 10: Lücke in KI-Framework PyTorch gefährdet Netzwerke – ML-Framework PyTorch ermöglicht Cyberattacken
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-luecke-pytorch-sicherheitstipps-updates-a-b036731dce3c4657d3070df45865f02e/
-
Kritische Schwachstelle CVE-2024-38428 in wget
Im Kommandozeilenprogramm wget gibt es eine kritische Schwachstelle, die mit dem CVSS Base Score 10.0 bewertet wird. CERT-Bund warnt vor der Schwachst… First seen on borncity.com Jump to article: www.borncity.com/blog/2024/06/18/kritische-schwachstelle-cve-2024-38428-in-wget-dringend-handeln/
-
Schwachstelle in IBM App Connect Enterprise Certified Container – CVSS 9.8 IBM schließt kritische Sicherheitslücke
First seen on security-insider.de Jump to article: www.security-insider.de/ibm-app-connect-enterprise-certified-container-schwachstelle-cve-2024-29651-a-b0ea419abca0ffae816e963d608a9298/
-
UEFIcanhazbufferoverflow: Widespread Impact from Vulnerability in Popular PC and Server Firmware
Summary Eclypsium Automata, our automated binary analysis system, has identified a high impact vulnerability (CVE-2024-0762 with a reported CVSS of 7…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/
-
Microsoft Windows Ntqueryinformationtoken Flaw Let Attackers Escalate Privileges
Microsofthas discloseda critical vulnerabilityidentified asCVE-2024-30088. With a CVSS score of 8.8, this flaw affects Microsoft Windows and allows lo… First seen on gbhackers.com Jump to article: gbhackers.com/microsoft-windows-ntqueryinformationtoken/
-
Patch Tuesday: Remote Code Execution Flaw in Microsoft Message Queuing
Tags: cvss, exploit, flaw, malicious, microsoft, remote-code-execution, update, vulnerability, windowsThe Windows vulnerability carries a CVSS severity score of 9.8/10 and can be exploited by via specially crafted malicious MSMQ packets. The post ows v… First seen on securityweek.com Jump to article: www.securityweek.com/patch-tuesday-remote-code-execution-flaw-in-microsoft-message-queuing/
-
Github Enterprise Server: Sicherheitslücke verleiht Angreifern Admin-Zugriff
Die Schwachstelle betrifft alle GHES-Versionen vor 3.13.0 und erreicht den größtmöglichen CVSS-Score von 10. Gefährdet sind Instanzen mit SAML-SSO-Aut… First seen on golem.de Jump to article: www.golem.de/news/github-enterprise-server-sicherheitsluecke-verleiht-angreifern-admin-zugriff-2405-185314.html
-
Critical Netflix Genie Bug Opens Big Data Orchestration to RCE
The severe security vulnerability (CVE-2024-4701, CVSS 9.9) gives remote attackers a way to burrow into Netflix’s Genie open source platform, which is… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/netflix-fixes-critical-vulnerability-on-big-data-orchestration-service
-
GitHub Issues Patch for Critical Exploit in Enterprise Server
The vulnerability affects all GHES versions prior to 3.13.0 and achieves the highest possible CVSS score of 10. Instances with SAML SSO authentication… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/github-issues-patch-for-critical-exploit-in-enterprise-server/
-
Intel’s Max Severity Flaw Affects AI Model Compressor Users
CVSS 10-Rated Bug Could Enable Hackers to Execute Arbitrary Code on Systems. A maximum-severity bug in Intel’s artificial intelligence model compressi… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/intels-max-severity-flaw-affects-ai-model-compressor-users-a-25275
-
BSI warnt vor Angriffen auf Palo-Alto-Firewalls: CVSS 10.0 – Kritische Schwachstellen in Firewalls ermöglichen Root-Zugriff
First seen on security-insider.de Jump to article: www.security-insider.de/bsi-warnt-vor-sicherheitsluecken-in-palo-alto-networks-firewalls-a-b9781c3b9b0e301d5f75ae896154fae9/
-
China Steals Defense Secrets ‘on Industrial Scale’
UNC5174¯â¤¯UNC302: CVSS 10 and 9.8 vulnerabilities exploited by Chinese threat actor for People’s Republic. The post €¯â¤¯UNC302: CVSS 10 and 9.8 vu… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/03/china-steals-secrets-f5-connectwise-richixbw/
-
CVSS 4.0 Offers Significantly More Patching Context
First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/mileage-orgs-will-get-from-cvss-4-0-will-vary
-
Ransomware Warning as CVSS 10.0 ScreenConnect Bug is Exploited
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-cvss-100-screenconnect/
-
CVE Prioritizer: Open-source tool to prioritize vulnerability patching
CVE Prioritizer is an open-source tool designed to assist in prioritizing the patching of vulnerabilities. It integrates data from CVSS, EPSS, and CIS… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/02/19/cve-prioritizer-open-source-vulnerability-patching/
-
1000+ JetBrains TeamCity Instances Vulnerable to RCE Bypass Attacks
A critical security vulnerability was detected in TeamCity On-Premises, tagged as CVE-2024-23917, with a CVSS score of 9.8. An unauthenticated attacke… First seen on gbhackers.com Jump to article: gbhackers.com/1000-jetbrains-teamcity-instances/
-
Schwachstellenbewertung – Was Sie unbedingt über CVSS wissen sollten!
Tags: cvssFirst seen on security-insider.de Jump to article: www.security-insider.de/was-sie-unbedingt-ueber-cvss-wissen-sollten-a-786c1ca5b92cca49f39f442977a8883c/
-
TeamCity Authentication Bypass Flaw Let Attackers Gain Admin Control
A critical security vulnerability was detected in TeamCity On-Premises, tagged as CVE-2024-23917, with a CVSS score of 9.8. An unauthenticated attacke… First seen on gbhackers.com Jump to article: gbhackers.com/teamcity-authentication-bypass-flaw/
-
Docker, Kubernetes und co.: Hacker können aus Containern auf Hostsysteme zugreifen
Die Schwachstellen dafür beziehen sich auf Buildkit und das CLI-Tool runc. Eine davon erreicht mit einem CVSS von 10 den maximal möglichen Schweregrad… First seen on golem.de Jump to article: www.golem.de/news/docker-kubernetes-und-co-hacker-koennen-aus-containern-auf-hostsysteme-zugreifen-2402-181875.html
-
Deutlich mehr Schwachstellen im Internet of Things (IoT)
Insgesamt wurden im ersten Halbjahr 2022 747 XIoT-Schwachstellen veröffentlicht, von denen die Mehrheit gemäß dem CVSS-Score als kritisch (19 %) oder … First seen on infopoint-security.de Jump to article: www.infopoint-security.de/deutlich-mehr-schwachstellen-im-internet-of-things-iot/a33053/
-
Mediaalert Qualys: CISA veröffentlicht Sicherheitshinweis mit dem Schweregrad CVSS 10.0
Diese Schwachstelle ist auf dem höchsten Schweregrad für CVSS, 10.0, eingestuft, da sie sich auf Installationen auswirken könnte. Die Schwachstelle is… First seen on infopoint-security.de Jump to article: www.infopoint-security.de/mediaalert-qualys-cisa-veroeffentlicht-sicherheitshinweis-mit-dem-schweregrad-cvss-10-0/a34131/
-
Twin Max-Severity Bugs Open Fortinet’s SIEM to Code Execution
Full 10s on the CVSS vulnerability severity scale have been assigned to two flaws discovered in Fortinet’s FortiSIEM cybersecurity operations platform… First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/fortinet-fortisiem-hit-with-twin-max-severity-bugs

