#CISA: #Vulnerability Summary for the Week of August 7, 2023

Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow

08/14/2023 05:00 PM EDT

The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. NVD is sponsored by CISA. In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available.

Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:

  • High: vulnerabilities with a CVSS base score of 7.0–10.0
  • Medium: vulnerabilities with a CVSS base score of 4.0–6.9
  • Low: vulnerabilities with a CVSS base score of 0.0–3.9

Entries may include additional information provided by organizations and efforts sponsored by CISA. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletin is compiled from external, open-source reports and is not a direct result of CISA analysis.

High Vulnerabilities

Primary
Vendor — Product
Description Published CVSS Score Source & Patch Info
phoenixcontact — wp_6xxx_series In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device. 2023-08-08 9.9 CVE-2023-3572
MISC
qualcomm_inc. — snapdragon Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder. 2023-08-08 9.8 CVE-2022-40510
MISC
microsoft — exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 2023-08-08 9.8 CVE-2023-21709
MISC
joomla — joomla Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability allows SQL Injection. 2023-08-07 9.8 CVE-2023-23757
MISC
joomla — joomla Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability allows SQL Injection. 2023-08-07 9.8 CVE-2023-23758
MISC
qualcomm_inc. — snapdragon Memory corruption in QESL while processing payload from external ESL device to firmware. 2023-08-08 9.8 CVE-2023-28561
MISC
pyrocms — pyrocms PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system. 2023-08-04 9.8 CVE-2023-29689
MISC
MISC
pega — pega_platform Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials 2023-08-07 9.8 CVE-2023-32090
MISC
paessler — prtg_network_monitor An issue was discovered in Paessler PRTG Network Monitor 23.2.83.1760. Due to command-line parameter injection and an undocumented debug feature flag, an attacker can utilize the HL7 sensor to write arbitrary data to the disk. This can be utilized to write a custom EXE(.bat) sensor, that will then run. This primitive gives remote code execution. 2023-08-09 9.8 CVE-2023-32781
MISC
MISC
paessler — prtg_network_monitor An issue was discovered in Paessler PRTG Network Monitor 23.2.83.1760. Due to command-line parameter injection and an undocumented debug feature flag, an attacker can utilize the DICOM sensor to write arbitrary data to the disk. This can be utilized to write a custom EXE(.bat) sensor, that will then run. This primitive gives remote code execution. 2023-08-09 9.8 CVE-2023-32782
MISC
MISC
assaabloy — control_id_idsecure A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server’s root directory, resulting in remote code execution. 2023-08-05 9.8 CVE-2023-33367
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device’s firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices, impersonating them. in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication. 2023-08-04 9.8 CVE-2023-33372
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices. 2023-08-04 9.8 CVE-2023-33373
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in arbitrary remote command execution. 2023-08-04 9.8 CVE-2023-33374
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over devices. 2023-08-04 9.8 CVE-2023-33375
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices. 2023-08-04 9.8 CVE-2023-33376
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices. 2023-08-04 9.8 CVE-2023-33377
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices. 2023-08-04 9.8 CVE-2023-33378
MISC
MISC
connected_io — connected_io Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of Connected IO’s devices. 2023-08-04 9.8 CVE-2023-33379
MISC
MISC
ai-dev — ai-table ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. 2023-08-04 9.8 CVE-2023-33665
MISC
MISC
a2technology — camera_trap_tracking_system Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in a2 Camera Trap Tracking System allows SQL Injection.This issue affects Camera Trap Tracking System: before 3.1905. 2023-08-08 9.8 CVE-2023-3386
MISC
joomla — joomla Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability allows SQL Injection. 2023-08-07 9.8 CVE-2023-34476
MISC
joomla — joomla Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability allows SQL Injection. 2023-08-07 9.8 CVE-2023-34477
MISC
wordpress — wordpress The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the ‘wp_abspath’ parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server. 2023-08-12 9.8 CVE-2023-3452
MISC
MISC
MISC
cszcms– cszcms A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL. 2023-08-09 9.8 CVE-2023-34545
MISC
MISC
a2technology — license_portal_system Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in a2 License Portal System allows SQL Injection.This issue affects License Portal System: before 1.48. 2023-08-08 9.8 CVE-2023-3522
MISC
microsoft — windows_server_2008 Microsoft Message Queuing Remote Code Execution Vulnerability 2023-08-08 9.8 CVE-2023-35385
MISC
langchain — langchain An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the PALChain,from_math_prompt(llm).run in the python exec method. 2023-08-05 9.8 CVE-2023-36095
MISC
MISC
MISC
phpjabbers — class_scheduling_system In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. 2023-08-04 9.8 CVE-2023-36134
MISC
MISC
phpjabbers — document_creator There is a SQL injection (SQLi) vulnerability in the “column” parameter of index.php in PHPJabbers Document Creator v1.0. 2023-08-10 9.8 CVE-2023-36311
MISC
MISC
aerospike — aerospike_java_client The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it encounters them without further validation. Attackers that manage to trick clients into communicating with a malicious server can include especially crafted objects in its responses that, once deserialized by the client, force it to execute arbitrary code. This can be abused to take control of the machine the client is running on. Versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 contain a patch for this issue. 2023-08-04 9.8 CVE-2023-36480
MISC
MISC
MISC
MISC
MISC
MISC
MISC
MISC
MISC
MISC
MISC
MISC
MISC
digital_ant — e-commerce_software Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Digital Ant E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 11. 2023-08-08 9.8 CVE-2023-3651
MISC
zoom — zoom_for_windows Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access. 2023-08-08 9.8 CVE-2023-36534
MISC
microsoft — windows_server_2008 Windows System Assessment Tool Elevation of Privilege Vulnerability 2023-08-08 9.8 CVE-2023-36903
MISC
microsoft — windows_server_2008 Microsoft Message Queuing Remote Code Execution Vulnerability 2023-08-08 9.8 CVE-2023-36910
MISC
microsoft — windows_server_2008 Microsoft Message Queuing Remote Code Execution Vulnerability 2023-08-08 9.8 CVE-2023-36911
MISC
oduyo — online_collection Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1. 2023-08-08 9.8 CVE-2023-3716
MISC
farmakom — remote_administration_console Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02. 2023-08-08 9.8 CVE-2023-3717
MISC
siemens — ruggedcom_crossbow A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database. 2023-08-08 9.8 CVE-2023-37372
MISC
metabase — metabase Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one’s Metabase server. The core issue is that one of the supported data warehouses (an embedded in-memory database H2), exposes a number of ways for a connection string to include code that is then executed by the process running the embedded database. Because Metabase allows users to connect to databases, this means that a user supplied string can be used to inject executable code. Metabase allows users to validate their connection string before adding a database (including on setup), and this validation API was the primary vector used as it can be called without validation. Versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4 fix this issue by removing the ability of users to add H2 databases entirely. As a workaround, it is possible to block these vulnerabilities at the network level by blocking the endpoints `POST /api/database`, `PUT /api/database/:id`, and `POST /api/setup/validateuntil`. Those who use H2 as a file-based database should migrate to SQLite. 2023-08-04 9.8 CVE-2023-37470
MISC
sap — powerdesigner SAP PowerDesigner – version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy. 2023-08-08 9.8 CVE-2023-37483
MISC
MISC
sourcecodester — judging_management_system Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php. 2023-08-08 9.8 CVE-2023-37682
MISC
MISC
hikashop — hikashop Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability allows SQL Injection. 2023-08-07 9.8 CVE-2023-38044
MISC
MISC
microsoft — windows_server_2022 Windows Mobile Device Management Elevation of Privilege Vulnerability 2023-08-08 9.8 CVE-2023-38186
MISC
minecraft — minecraft Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java’s `ObjectInputStream#readObject` on untrusted data coming from clients or servers over the network resulting in possible remote code execution when sending specifically crafted network packets after connecting. The affected versions were released between 2013 and 2016 and the issue (back then unknown) was fixed in 2016 by a refactoring of the network IO code. The issue is present in all Logistics Pipes versions ranged from 0.7.0.91 prior to 0.10.0.71, which were downloaded from different platforms summing up to multi-million downloads. For Minecraft version 1.7.10 the issue was fixed in build 0.10.0.71. Everybody on Minecraft 1.7.10 should check their version number of Logistics Pipes in their modlist and update, if the version number is smaller than 0.10.0.71. Any newer supported Minecraft version (like 1.12.2) never had a Logistics Pipes version with vulnerable code. The best available workaround for vulnerable versions is to play in singleplayer only or update to newer Minecraft versions and modpacks. 2023-08-04 9.8 CVE-2023-38689
MISC
MISC
MISC
matrix — matrix_irc_bridge matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge bot. Versions 1.0.1 and above are patched. There are no robust workarounds to the bug. One may disable dynamic channels in the config to disable the most common execution method but others may exist. 2023-08-04 9.8 CVE-2023-38690
MISC
MISC
MISC
fit2cloud — cloudexplorer_lite CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading. 2023-08-04 9.8 CVE-2023-38692
MISC
MISC
MISC
datadoghq — import-in-the-middle import-in-the-middle is a module loading interceptor specifically for ESM modules. The import-in-the-middle loader works by generating a wrapper module on the fly. The wrapper uses the module specifier to load the original module and add some wrapping code. Prior to version 1.4.2, it allows for remote code execution in cases where an application passes user-supplied input directly to the `import()` function. This vulnerability has been patched in import-in-the-middle version 1.4.2. Some workarounds are available. Do not pass any user-supplied input to `import()`. Instead, verify it against a set of allowed values. If using import-in-the-middle, directly or indirectly, and support for EcmaScript Modules is not needed, ensure that no options are set, either via command-line or the `NODE_OPTIONS` environment variable, that would enable loader hooks. 2023-08-07 9.8 CVE-2023-38704
MISC
MISC
netgear — r7100lg_firmware Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi. 2023-08-07 9.8 CVE-2023-38928
MISC
MISC
tenda — 4g300_firmware Tenda 4G300 v1.01.42 was discovered to contain a stack overflow via the page parameter at /VirtualSer. 2023-08-07 9.8 CVE-2023-38929
MISC
tenda — ac7_firmware Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function. 2023-08-07 9.8 CVE-2023-38930
MISC
tenda — ac10_firmware Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function. 2023-08-07

Discover more from #News247WorldPress

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading