2025年1月8日星期三

Aruba 產品多個漏洞

發佈日期: 2025年01月08日

風險: 高度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

在Aruba產品發現多個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意:

針對這些漏洞之一的概念驗證碼已被公開。


影響

  • 遠端執行程式碼

受影響之系統或技術

HPE Aruba Networking

  • 501 Wireless Client Bridge

Affected Software Version(s):

  • V2.1.1.0-B0030 及之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Aruba Products Multiple Vulnerabilities

Release Date: 8 Jan 2025

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

Proof Of Concept Exploit Code is publicly available for one of these vulnerabilities.

 

 


Impact

  • Remote Code Execution

System / Technologies affected

HPE Aruba Networking

  • 501 Wireless Client Bridge

Affected Software Version(s):

  • V2.1.1.0-B0030 and below

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

OpenVPN 資料洩露漏洞

發佈日期: 2025年01月08日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 OpenVPN 發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發洩露敏感資料。

 

影響

  • 資料洩露

受影響之系統或技術

  • OpenVPN Connect 3.5.0 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

OpenVPN Information Disclosure Vulnerability

Release Date: 8 Jan 2025

RISK: Medium Risk

TYPE: Servers - Other Servers

A vulnerability was identified in OpenVPN. A remote attacker could exploit this vulnerability to trigger sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure

System / Technologies affected

  • OpenVPN Connect version before 3.5.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

2025年1月7日星期二

三星產品多個漏洞

發佈日期: 2025年01月07日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行程式碼、繞過保安限制、篡改及敏感資料洩露。

 


影響

  • 阻斷服務
  • 權限提升
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400
  • Galaxy Watch running Android Watch 13, 14
  • Samsung mobile devices running Android 12, 13, 14

有關受影響產品,請參閱以下連結:

https://security.samsungmobile.com/securityUpdate.smsb

https://semiconductor.samsung.com/support/quality-support/product-security-updates/


解決方案

在安裝軟件之前,請先瀏覽供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Samsung Products Multiple Vulnerabilities

Release Date: 7 Jan 2025

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, security restriction bypass, data manipulation and sensitive information disclosure on the targeted system.

 


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400
  • Galaxy Watch running Android Watch 13, 14
  • Samsung mobile devices running Android 12, 13, 14

For affected products, please refer to the link below:

https://security.samsungmobile.com/securityUpdate.smsb

https://semiconductor.samsung.com/support/quality-support/product-security-updates/


Solutions

Before installation of the software, please visit the vendor website for more details.


Vulnerability Identifier


Source


Related Link

2025年1月6日星期一

NetApp 產品多個漏洞

發佈日期: 2025年01月06日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 NetApp 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 篡改
  • 資料洩露

受影響之系統或技術

  • ONTAP Select Deploy administration utility
  • ONTAP tools for VMware vSphere 9
  • ONTAP tools for VMware vSphere 10

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

NetApp Products Multiple Vulnerabilities

Release Date: 6 Jan 2025

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in NetApp Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Information Disclosure

System / Technologies affected

  • ONTAP Select Deploy administration utility
  • ONTAP tools for VMware vSphere 9
  • ONTAP tools for VMware vSphere 10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

2025年1月1日星期三

Palo Alto PAN-OS 阻斷服務狀況漏洞

發佈日期: 2024年12月30日

風險: 高度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

在 Palo Alto PAN-OS 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。

 

注意:

防火牆配置必須擁有DNS Security License或Advanced DNS Security License,並且DNS Security logging必須已經啓用,才可能被遠端攻擊者濫用。

 

CVE-2024-3393漏洞正被廣泛利用。CVE-2024-3393漏洞會使防火墻進入維護模式。


影響

  • 阻斷服務

受影響之系統或技術

  • PAN-OS >= 10.1.14, < 10.1.15 的版本
  • PAN-OS >= 10.2.8, < 10.2.14 的版本
  • PAN-OS 11.1.5 之前的版本
  • PAN-OS 11.2.3 之前的版本
  • PAN-OS Prisma Access >= 10.2.8, < 11.2.3 的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Palo Alto PAN-OS Denial Of Service Vulnerability

Release Date: 30 Dec 2024

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

A vulnerability was identified in Palo Alto PAN-OS. A remote attacker can exploit this vulnerability to trigger denial of service condition on the targeted system.

 

Note:

The firewall configuration must have either a DNS Security License or an Advanced DNS Security License, AND DNS Security logging must be enabled for this issue to be misused by a remote attacker.

 

CVE-2024-3393 is being exploited in the wild. Exploitation of CVE-2024-3393 will cause the firewall to enter maintenance mode.


Impact

  • Denial of Service

System / Technologies affected

  • PAN-OS 10.1 versions >= 10.1.14, < 10.1.15
  • PAN-OS 10.2 versions >= 10.2.8, < 10.2.14
  • PAN-OS 11.1 versions earlier than PAN-OS 11.1.5
  • PAN-OS 11.2 versions earlier than PAN-OS 11.2.3
  • PAN-OS Prisma Access versions >= 10.2.8, < 11.2.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2024年12月25日星期三

Adobe ColdFusion資料洩露漏洞

發佈日期: 2024年12月24日

風險: 高度風險

類型: 用戶端 - 辦公室應用

於 Adobe ColdFusion發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發洩露敏感資料及篡改。

 

注意:

CVE-2024-53961 的概念驗證碼已被公開。

 

影響

  • 資料洩露
  • 篡改

受影響之系統或技術

  • ColdFusion 2021 - Update 17 及以前的版本
  • ColdFusion 2023 - Update 11 及以前的版本
 

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 24 日 於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。   注意 : 針對 WordPress 新發現的漏洞 CVE-202...