Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » CISA flags 6 vulnerabilities – Apple, Apache, Adobe, D-Link, Joomla under attack
    Cyber Security

    CISA flags 6 vulnerabilities – Apple, Apache, Adobe, D-Link, Joomla under attack

    techempireBy techempireNo Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 10, 2024Editorial DepartmentPatch Management/Threat Intelligence

    CISA flagged 6 vulnerabilities

    Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

    These include CVE-2023-27524 (CVSS score: 8.9), which is a high-severity vulnerability affecting the Apache Superset open source data visualization software, which can achieve remote code execution. Fixed in version 2.1.

    Details of the issue first came to light in April 2023, with Horizon3.ai’s Naveen Sunkavally describing it as “a dangerous default configuration in Apache Superset that allows unauthenticated attackers to obtain remote programs.” code execution, obtaining credentials and exfiltrating data.”

    Internet security

    It’s unclear how the vulnerability was exploited in the wild. CISA also added five other flaws –

    • CVE-2023-38203 (CVSS Rating: 9.8) – Adobe ColdFusion Deserialization Untrusted Data Vulnerability
    • CVE-2023-29300 (CVSS Rating: 9.8) – Adobe ColdFusion Deserialization Untrusted Data Vulnerability
    • CVE-2023-41990 (CVSS Rating: 7.8) – Apple Multi-Product Code Execution Vulnerability
    • CVE-2016-20017 (CVSS Rating: 9.8) – D-Link DSL-2750B Device Command Injection Vulnerability
    • CVE-2023-23752 (CVSS Rating: 5.3) – Joomla!Improper Access Control Vulnerability

    Notably, CVE-2023-41990, which Apple patched in iOS 15.7.8 and iOS 16.3, was used by unknown attackers as part of a triangulation spyware attack to enable remote code when processing specially crafted iMessage PDF attachments. implement.

    Federal Civilian Executive Branch (FCEB) agencies are recommended to fix the above errors before January 29, 2024, to protect their networks from active threats.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.