2024年11月18日星期一

Ruckus Products Remote Code Execution Vulnerability

Release Date: 18 Nov 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

A vulnerability was identified in Ruckus Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 


Impact

  • Remote Code Execution

System / Technologies affected

  • RUCKUS H350
  • RUCKUS H550
  • RUCKUS R350
  • RUCKUS R350e
  • RUCKUS R670
  • RUCKUS T350c
  • RUCKUS T350d
  • RUCKUS T350se
  • RUCKUS T670
  • Ruckus Q410
  • Ruckus Q710
  • Ruckus Q910
  • Ruckus R550
  • Ruckus R560
  • Ruckus R650
  • Ruckus R750
  • Ruckus R760
  • Ruckus R770
  • Ruckus R850
  • Ruckus T750
  • Ruckus T750SE
  • SmartZone 144 (SZ-144)
  • SmartZone 144 (SZ-144) - Federal
  • SmartZone 300 (SZ300)
  • SmartZone 300 (SZ300) - Federal
  • Unleashed and Multi-Site Manager
End-of-Life (EOL) Products:

 

  • RUCKUS T811-CM (Non-SFP)
  • RUCKUS T811-CM
  • Ruckus C110
  • Ruckus C500
  • Ruckus E510
  • Ruckus H320
  • Ruckus H500
  • Ruckus H510
  • Ruckus P300
  • Ruckus R300
  • Ruckus R310
  • Ruckus R320
  • Ruckus R500
  • Ruckus R510
  • Ruckus R600
  • Ruckus R610
  • Ruckus R700
  • Ruckus R710
  • Ruckus R720
  • Ruckus R730
  • Ruckus T300
  • Ruckus T301n
  • Ruckus T301s
  • Ruckus T310c
  • Ruckus T310d
  • Ruckus T310n
  • Ruckus T310s
  • Ruckus T504
  • Ruckus T610
  • Ruckus T710
  • Ruckus T710s
  • SmartCell Gateway 200 (SCG200)
  • SmartZone 100 (SZ-100)
  • SmartZone 100-D (SZ100-D)
  • ZoneDirector 1100
  • ZoneDirector 1200
  • ZoneDirector 3000

 


Solutions

Before installation of the software, please visit the vendor's web-site for more details.

 

Note: All end-of-life products do not receive security fixes.


Vulnerability Identifier

Note: No CVE information is available for this vulnerability


Source


Related Link

2024年11月15日星期五

Citrix 產品多個漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 操作系統 - Network

於 Citrix 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及遠端執行任意程式碼。

 

注意:

CVE-2024-8068 和 CVE-2024-8069的概念驗證碼已被公開。攻擊者在利用漏洞之前需要經過身份驗證。因此,風險等級為中度風險。

 


影響

  • 遠端執行程式碼
  • 權限提升
  • 阻斷服務

受影響之系統或技術

  • Citrix Virtual Apps and Desktops 2407 中 24.5.200.8 之前的版本
  • Citrix Virtual Apps and Desktops 1912 LTSR 中 CU9 hotfix 19.12.9100.6 之前的版本
  • Citrix Virtual Apps and Desktops 2203 LTSR 中 CU5 hotfix 22.03.5100.11 之前的版本
  • Citrix Virtual Apps and Desktops 2402 LTSR 中 CU1 hotfix 24.02.1200.16 之前的版本
  • NetScaler ADC 和 NetScaler Gateway 14.1 中 14.1-29.72 之前的版本
  • NetScaler ADC 和 NetScaler Gateway 13.1 中 13.1-55.34 之前的版本
  • NetScaler ADC 13.1-FIPS 中 13.1-37.207 之前的版本
  • NetScaler ADC 12.1-FIPS 中 12.1-55.321 之前的版本
  • NetScaler ADC 12.1-NDcPP 中 12.1-55.321 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Citrix Products Multiple Vulnerabilities

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and remote code execution on the targeted system.

 

Note:

Proof of concept exploit for CVE-2024-8068 and CVE-2024-8069 exists on the internet. Attacker needs to be authenticated before exploiting the vulunbilities. Hence, the overall risk is rated as Medium Risk. 

 


Impact

  • Remote Code Execution
  • Elevation of Privilege
  • Denial of Service

System / Technologies affected

  • Citrix Virtual Apps and Desktops before 2407 hotfix 24.5.200.8
  • Citrix Virtual Apps and Desktops 1912 LTSR before CU9 hotfix 19.12.9100.6
  • Citrix Virtual Apps and Desktops 2203 LTSR before CU5 hotfix 22.03.5100.11
  • Citrix Virtual Apps and Desktops 2402 LTSR before CU1 hotfix 24.02.1200.16
  • NetScaler ADC and NetScaler Gateway 14.1 before  14.1-29.72
  • NetScaler ADC and NetScaler Gateway 13.1  before  13.1-55.34
  • NetScaler ADC 13.1-FIPS before  13.1-37.207
  • NetScaler ADC 12.1-FIPS before  12.1-55.321
  • NetScaler ADC 12.1-NDcPP before  12.1-55.321

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Fortinet 產品多個漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 操作系統 - Network

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料、繞過保安限制、篡改及權限提升。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制
  • 篡改
  • 權限提升

受影響之系統或技術

FortiAnalyzer

  • FortiAnalyzer 6.2 所有版本
  • FortiAnalyzer 6.4 所有版本
  • FortiAnalyzer 7.0 所有版本
  • FortiAnalyzer 7.2 版本 7.2.0 至 7.2.5
  • FortiAnalyzer 7.4 版本 7.4.0 至 7.4.2

FortiAnalyzer-BigData

  • FortiAnalyzer-BigData 6.2 所有版本
  • FortiAnalyzer-BigData 6.4 所有版本
  • FortiAnalyzer-BigData 7.0 所有版本
  • FortiAnalyzer-BigData 7.2 版本 7.2.0 至 7.2.7
  • FortiAnalyzer-BigData 7.4 版本 7.4.0

FortiManager

  • FortiManager 6.2 所有版本
  • FortiManager 6.4 所有版本
  • FortiManager 7.0 所有版本
  • FortiManager 7.2 版本 7.2.0 至 7.2.5
  • FortiManager 7.4 版本 7.4.0 至 7.4.2

FortiOS

  • FortiOS 6.0 所有版本
  • FortiOS 6.2 所有版本
  • FortiOS 6.4 所有版本
  • FortiOS 7.0 所有版本
  • FortiOS 7.2 版本 7.2.0 至 7.2.8
  • FortiOS 7.4 版本 7.4.0 至 7.4.3

FortiProxy

  • FortiProxy 1.0 所有版本
  • FortiProxy 1.1 所有版本
  • FortiProxy 1.2 所有版本
  • FortiProxy 2.0 所有版本
  • FortiProxy 7.0 版本 7.0.0 至 7.0.16
  • FortiProxy 7.2 版本 7.2.0 至 7.2.9
  • FortiProxy 7.4 版本 7.4.0 至 7.4.3

FortiClientWindows

  • FortiClientWindows 6.4 所有版本
  • FortiClientWindows 7.0 版本 7.0.0 至 7.0.12
  • FortiClientWindows 7.2 版本 7.2.0 至 7.2.4
  • FortiClientWindows 7.4 版本 7.4.0

FortiClientMac

  • FortiClientMac 6.4 所有版本
  • FortiClientMac 7.0 版本 7.0.0 至 7.0.10
  • FortiClientMac 7.2 版本 7.2.0 至 7.2.4
  • FortiClientMac 7.4 版本 7.4.0

FortiWeb

  • FortiWeb 6.3 所有版本
  • FortiWeb 7.0 所有版本
  • FortiWeb 7.2 所有版本
  • FortiWeb 7.4 版本 7.4.0 至 7.4.3
  • FortiWeb 7.6 版本 7.6.0

FortiSwitchManager

  • FortiSwitchManager 7.0 版本 7.0.0 至 7.0.3
  • FortiSwitchManager 7.2 版本 7.2.0 至 7.2.3

FortiPAM

  • FortiPAM 1.0 所有版本
  • FortiPAM 1.1 所有版本
  • FortiPAM 1.2 所有版本

FortiPortal

  • FortiPortal 5.3 所有版本
  • FortiPortal 6.0 版本 6.0.0 至 6.0.14

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Multiple Vulnerabilities

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure, security restriction bypass, data manipulation, and elevation of privilege on the targeted system.

 


Impact

  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass
  • Data Manipulation
  • Elevation of Privilege

System / Technologies affected

FortiAnalyzer

  • FortiAnalyzer 6.2 all versions
  • FortiAnalyzer 6.4 all versions
  • FortiAnalyzer 7.0 all versions
  • FortiAnalyzer 7.2 version 7.2.0 through 7.2.5
  • FortiAnalyzer 7.4 version 7.4.0 through 7.4.2

FortiAnalyzer-BigData

  • FortiAnalyzer-BigData 6.2 all versions
  • FortiAnalyzer-BigData 6.4 all versions
  • FortiAnalyzer-BigData 7.0 all versions
  • FortiAnalyzer-BigData 7.2 version 7.2.0 through 7.2.7
  • FortiAnalyzer-BigData 7.4 version 7.4.0

FortiManager

  • FortiManager 6.2 all versions
  • FortiManager 6.4 all versions
  • FortiManager 7.0 all versions
  • FortiManager 7.2 version 7.2.0 through 7.2.5
  • FortiManager 7.4 version 7.4.0 through 7.4.2

FortiOS

  • FortiOS 6.0 all versions
  • FortiOS 6.2 all versions
  • FortiOS 6.4 all versions
  • FortiOS 7.0 all versions
  • FortiOS 7.2 version 7.2.0 through 7.2.8
  • FortiOS 7.4 version 7.4.0 through 7.4.3

FortiProxy

  • FortiProxy 1.0 all versions
  • FortiProxy 1.1 all versions
  • FortiProxy 1.2 all versions
  • FortiProxy 2.0 all versions
  • FortiProxy 7.0 version 7.0.0 through 7.0.16
  • FortiProxy 7.2 version 7.2.0 through 7.2.9
  • FortiProxy 7.4 version 7.4.0 through 7.4.3

FortiClientWindows

  • FortiClientWindows 6.4 all versions
  • FortiClientWindows 7.0 version 7.0.0 through 7.0.12
  • FortiClientWindows 7.2 version 7.2.0 through 7.2.4
  • FortiClientWindows 7.4 version 7.4.0

FortiClientMac

  • FortiClientMac 6.4 all versions
  • FortiClientMac 7.0 version 7.0.0 through 7.0.10
  • FortiClientMac 7.2 version 7.2.0 through 7.2.4
  • FortiClientMac 7.4 version 7.4.0

FortiWeb

  • FortiWeb 6.3 all versions
  • FortiWeb 7.0 all versions
  • FortiWeb 7.2 all versions
  • FortiWeb 7.4 version 7.4.0 through 7.4.3
  • FortiWeb 7.6 version 7.6.0

FortiSwitchManager

  • FortiSwitchManager 7.0 version 7.0.0 through 7.0.3
  • FortiSwitchManager 7.2 version 7.2.0 through 7.2.3

FortiPAM

  • FortiPAM 1.0 all versions
  • FortiPAM 1.1 all versions
  • FortiPAM 1.2 all versions

FortiPortal

  • FortiPortal 5.3 all versions
  • FortiPortal 6.0 version 6.0.0 through 6.0.14

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

GitLab 多個漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、跨網站指令碼、遠端執行任意程式碼、繞過保安限制及敏感資料洩露。


影響

  • 阻斷服務
  • 跨網站指令碼
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • GitLab Community Edition (CE) 17.3.7, 17.4.4 及 17.5.2 以前的版本
  • GitLab Enterprise Edition (EE) 17.3.7, 17.4.4 及 17.5.2 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit these vulnerabilities to trigger denial of service, cross-site scripting, remote code execution, security restriction bypass, and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Cross-Site Scripting
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 17.3.7, 17.4.4 and 17.5.2
  • GitLab Enterprise Edition (EE) versions prior to 17.3.7, 17.4.4 and 17.5.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Ivanti 產品多個漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 操作系統 - Network

於 Ivanti 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、權限提升、篡改及敏感資料洩露。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 權限提升
  • 篡改

受影響之系統或技術

  • Ivanti Avalanche 版本 6.4.5 及更早版本
  • Ivanti Connect Secure (ICS) 版本 22.7R2.2 及更早版本
  • Ivanti Policy Secure (IPS) 版本 22.7R1.1 及更早版本
  • Ivanti Secure Access Client (ISAC) 版本 22.7R3 及更早版本
  • Ivanti Endpoint Manager (EPM) 2022 SU6 9 月安全性更新及之前版本
  • Ivanti Endpoint Manager (EPM) 2024 年 9 月安全性更新及之前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Ivanti Products Multiple Vulnerabilities

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities have been identified in Ivanti Products. A remote attacker could exploit these vulnerability to trigger denial of service condition, remote code execution, elevation of privilege, data manipulation and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege
  • Data Manipulation

System / Technologies affected

  • Ivanti Avalanche versions 6.4.5 and prior
  • Ivanti Connect Secure (ICS) versions 22.7R2.2 and prior
  • Ivanti Policy Secure (IPS) versions 22.7R1.1 and prior
  • Ivanti Secure Access Client (ISAC) versions 22.7R3 and prior
  • Ivanti Endpoint Manager (EPM) 2022 SU6 September security update and prior
  • Ivanti Endpoint Manager (EPM) 2024 September security update and prior

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發敏感資料洩露、繞過保安限制、及遠端執行任意程式碼。


Microsoft Edge Multiple Vulnerabilities

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, security restriction bypass and remote code execution on the targeted system.


Mozilla Thunderbird 資料洩露漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla Thunderbird 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發敏感資料洩露。


影響

  • 資料洩露

受影響之系統或技術

以下版本之前的版本﹕

 

  • Thunderbird 128.4.3
  • Thunderbird 132.0.1

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Thunderbird 128.4.3
  • Thunderbird 132.0.1

漏洞識別碼


資料來源


相關連結

Mozilla Thunderbird Information Disclosure Vulnerability

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Mozilla Thunderbird. A remote attacker could exploit this vulnerability to trigger sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure

System / Technologies affected

Versions prior to:

 

  • Thunderbird 128.4.3
  • Thunderbird 132.0.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Thunderbird 128.4.3
  • Thunderbird 132.0.1

Vulnerability Identifier


Source


Related Link

Palo Alto PAN-OS 多個漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

於 Palo Alto PAN-OS 發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、端執行任意程式碼、阻斷服務狀況、敏感資料洩露及繞過保安限制。

 


影響

  • 跨網站指令碼
  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • PAN-OS 10.1.7 之前的 PAN-OS 10.1 版本
  • PAN-OS 10.1.10 之前的 PAN-OS 10.1 版本
  • PAN-OS 10.1.11 之前的 PAN-OS 10.1 版本
  • PAN-OS 10.1.14 之前的 PAN-OS 10.1 版本
  • PAN-OS 10.2.2 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.4-h5 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.4-h6 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.5 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.7-h16 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.8-h13 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.9-14 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.10-h7 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.11 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.11-h4 之前的 PAN-OS 10.2 版本
  • PAN-OS 10.2.12 之前的 PAN-OS 10.2 版本
  • PAN-OS 11.0.2 之前的 PAN-OS 11.0 版本
  • PAN-OS 11.0.3 之前的 PAN-OS 11.0 版本
  • PAN-OS 11.0.5 之前的 PAN-OS 11.0 版本
  • PAN-OS 11.0.6 之前的 PAN-OS 11.0 版本
  • PAN-OS 11.1.2-h14 之前的 PAN-OS 11.1 版本
  • PAN-OS 11.1.3-h10 之前的 PAN-OS 11.1 版本
  • PAN-OS 11.1.4 之前的 PAN-OS 11.1 版本
  • PAN-OS 11.1.5 之前的 PAN-OS 11.1 版本
  • PAN-OS 11.2.2-h3 之前的 PAN-OS 11.2 版本
  • PAN-OS 11.2.3 之前的 PAN-OS 11.2 版本
  • PAN-OS 11.2.4 之前的 PAN-OS 11.2 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Palo Alto PAN-OS Multiple vulnerabilities

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Palo Alto PAN-OS. A remote user could exploit these vulnerabilities to trigger cross-site scripting, remote code execution, denial of service, sensitive information disclosure, and security restriction bypass on the targeted system.


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • PAN-OS 10.1 versions earlier than PAN-OS 10.1.7
  • PAN-OS 10.1 versions earlier than PAN-OS 10.1.10
  • PAN-OS 10.1 versions earlier than PAN-OS 10.1.11
  • PAN-OS 10.1 versions earlier than PAN-OS 10.1.14
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.2
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.4-h5
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.4-h6
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.5
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.7-h16
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.8-h13
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.9-14
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.10-h7
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.11
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.11-h4
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.12
  • PAN-OS 11.0 versions earlier than PAN-OS 11.0.2
  • PAN-OS 11.0 versions earlier than PAN-OS 11.0.3
  • PAN-OS 11.0 versions earlier than PAN-OS 11.0.5
  • PAN-OS 11.0 versions earlier than PAN-OS 11.0.6
  • PAN-OS 11.1 versions earlier than PAN-OS 11.1.2-h14
  • PAN-OS 11.1 versions earlier than PAN-OS 11.1.3-h10
  • PAN-OS 11.1 versions earlier than PAN-OS 11.1.4
  • PAN-OS 11.1 versions earlier than PAN-OS 11.1.5
  • PAN-OS 11.2 versions earlier than PAN-OS 11.2.2-h3
  • PAN-OS 11.2 versions earlier than PAN-OS 11.2.3
  • PAN-OS 11.2 versions earlier than PAN-OS 11.2.4

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

Xen 多個漏洞

發佈日期: 2024年11月15日

風險: 中度風險

類型: 操作系統 - LINUX

於 Xen 發現多個漏洞,攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及敏感資料洩露。


影響

  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • Xen 版本 4.6 至 4.19
  • Xen 版本 4.8 及更高版本
  • 運行 HVM guests的 x86 系統
  • 運行 PVH guests的 x86 系統

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。


漏洞識別碼


資料來源


相關連結

Xen Multiple Vulnerabilities

Release Date: 15 Nov 2024

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities have been identified in Xen. An attacker can exploit these vulnerabilities to trigger denial of service condition and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Xen versions 4.6 through 4.19
  • Xen versions 4.8 and onwards
  • x86 systems running HVM guests
  • x86 systems running PVH guests

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link

2024年11月13日星期三

Adobe 每月保安更新 (2024年11月)

發佈日期: 2024年11月13日

風險: 中度風險

類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Bridge中度風險 中度風險資料洩露
阻斷服務
 APSB24-77
Adobe Audition中度風險 中度風險資料洩露 APSB24-83
Adobe After Effects中度風險 中度風險遠端執行程式碼
資料洩露
 APSB24-85
Substance 3D Painter中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
 APSB24-86
Adobe Illustrator中度風險 中度風險遠端執行程式碼
資料洩露
阻斷服務
 APSB24-87
Adobe InDesign中度風險 中度風險遠端執行程式碼
資料洩露
 APSB24-88
Adobe Photoshop中度風險 中度風險遠端執行程式碼 APSB24-89
Adobe Commerce中度風險 中度風險遠端執行程式碼 APSB24-90

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:8

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 資料洩露
  • 阻斷服務

受影響之系統或技術

  • Adobe Bridge  13.0.9 及以前版本
  • Adobe Bridge  14.1.2 及以前版本
  • Adobe Audition 24.4.6 及以前版本
  • Adobe Audition 23.6.9 及以前版本
  • Adobe After Effects 24.6.2 及以前版本
  • Adobe After Effects 23.6.9 及以前版本
  • Adobe Substance 3D Painter 10.1.0 及以前版本
  • Illustrator 2024 28.7.1 及以前版本
  • Adobe InDesign ID19.5 及以前版本
  • Adobe InDesign ID18.5.3 及以前版本
  • Adobe InDesign ID18.5.2 及以前版本
  • Photoshop 2023 24.7.3 及以前版本
  • Photoshop 2024 25.11 及以前版本
  • Adobe Commerce and Magento Open Source powered by Commerce Services and deployed as SaaS (software as a service). (Commerce Services Connector) 3.2.5 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (November 2024)

Release Date: 13 Nov 2024

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe BridgeMedium Risk Medium RiskInformation Disclosure
Denial of Service
 APSB24-77
Adobe AuditionMedium Risk Medium RiskInformation Disclosure APSB24-83
Adobe After EffectsMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB24-85
Substance 3D PainterMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
 APSB24-86
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution
Information Disclosure
Denial of Service
 APSB24-87
Adobe InDesignMedium Risk Medium RiskRemote Code Execution
Information Disclosure
 APSB24-88
Adobe PhotoshopMedium Risk Medium RiskRemote Code Execution APSB24-89
Adobe CommerceMedium Risk Medium RiskRemote Code Execution APSB24-90

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 8

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Information Disclosure
  • Denial of Service

System / Technologies affected

  • Adobe Bridge  13.0.9 and earlier versions
  • Adobe Bridge  14.1.2 and earlier versions
  • Adobe Audition 24.4.6 and earlier versions
  • Adobe Audition 23.6.9 and earlier versions
  • Adobe After Effects 24.6.2 and earlier versions
  • Adobe After Effects 23.6.9 and earlier versions
  • Adobe Substance 3D Painter 10.1.0 and earlier versions
  • Illustrator 2024 28.7.1 and earlier versions
  • Adobe InDesign ID19.5 and earlier versions
  • Adobe InDesign ID18.5.3 and earlier versions
  • Adobe InDesign ID18.5.2 and earlier versions
  • Photoshop 2023 24.7.3 and earlier versions
  • Photoshop 2024 25.11 and earlier versions
  • Adobe Commerce and Magento Open Source powered by Commerce Services and deployed as SaaS (software as a service). (Commerce Services Connector) 3.2.5 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...