#CISA: #Vulnerability Summary for the Week of August 14, 2023

Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow

08/21/2023 3:00 PM EDT

The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. NVD is sponsored by CISA. In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. Please visit NVD for updated vulnerability entries, which include CVSS scores once they are available.

Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:

  • High: vulnerabilities with a CVSS base score of 7.0–10.0
  • Medium: vulnerabilities with a CVSS base score of 4.0–6.9
  • Low: vulnerabilities with a CVSS base score of 0.0–3.9

Entries may include additional information provided by organizations and efforts sponsored by CISA. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletin is compiled from external, open-source reports and is not a direct result of CISA analysis. 

High Vulnerabilities

Primary
Vendor — Product
Description Published CVSS Score Source & Patch Info
foldingathome — client_advanced_control An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remote attackers to execute arbitrary code via crafted payload to function parse_message in file Connection.py. 2023-08-11 9.8 CVE-2020-27544
MISC
sourcecodester — school_faculty_scheduling_system SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php. 2023-08-11 9.8 CVE-2020-36034
MISC
MISC
MISC
bloofox — bloofoxcms File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module. 2023-08-11 9.8 CVE-2020-36082
MISC
hello.js_project — hello.js Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function. 2023-08-11 9.8 CVE-2021-26505
MISC
open-falcon — dashboard An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface. 2023-08-11 9.8 CVE-2021-27523
MISC
ruoyi — ruoyi An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges. 2023-08-11 9.8 CVE-2021-28411
MISC
intel(r) — ethernet_controller_rdma_driver_for_linux Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version 1.9.30 may allow an unauthenticated user to potentially enable escalation of privilege via network access. 2023-08-11 9.8 CVE-2023-25775
MISC
wordpress — wordpress The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the ‘wp_abspath’ parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server. 2023-08-12 9.8 CVE-2023-3452
MISC
MISC
MISC
novel-plus — novel-plus novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability. 2023-08-14 9.8 CVE-2023-37847
MISC
MISC
MISC
huawei — emui Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges. 2023-08-13 9.8 CVE-2023-39405
MISC
MISC
schoolmate — schoolmate Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php. 2023-08-15 9.8 CVE-2023-39850
MISC
MISC
veritas — netbackup_snapshot_manager A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and integrity of messages controlling the backup and restore jobs, and could result in the service becoming unavailable. This impacts only the jobs controlling the backup and restore activities, and does not allow access to (or deletion of) the backup snapshot data itself. This vulnerability is confined to the NetBackup Snapshot Manager feature and does not impact the RabbitMQ instance on the NetBackup primary servers. 2023-08-11 9.8 CVE-2023-40256
MISC
gitpython — gitpython GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. 2023-08-11 9.8 CVE-2023-40267
MISC
MISC
intel(r) — manageability_commander Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access. 2023-08-11 9.6 CVE-2022-29887
MISC
intel(r) — driver_support_assistant Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access. 2023-08-11 9.6 CVE-2023-27515
MISC
zrlog — zrlog Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS). 2023-08-11 9.1 CVE-2020-27514
MISC
huawei — emui Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop. 2023-08-13 9.1 CVE-2021-46895
MISC
MISC
huawei — emui Vulnerability of configuration defects in the media module of certain products. Successful exploitation of this vulnerability may cause unauthorized access. 2023-08-13 9.1 CVE-2023-39385
MISC
MISC
huawei — emui Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. 2023-08-13 9.1 CVE-2023-39398
MISC
MISC
huawei — emui Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. 2023-08-13 9.1 CVE-2023-39399
MISC
MISC
huawei — emui Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. 2023-08-13 9.1 CVE-2023-39400
MISC
MISC
huawei — emui Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. 2023-08-13 9.1 CVE-2023-39401
MISC
MISC
huawei — emui Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. 2023-08-13 9.1 CVE-2023-39402
MISC
MISC
huawei — emui Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. 2023-08-13 9.1 CVE-2023-39403
MISC
MISC
yzmcms — yzmcms Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint. 2023-08-11 8.8 CVE-2020-23595
MISC
xuxueli — xxl-job Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file. 2023-08-11 8.8 CVE-2020-24922
MISC
thedaylightstudio — fuel_cms SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items. 2023-08-11 8.8 CVE-2020-24950
MISC
churchcrm — churchcrm CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file. 2023-08-11 8.8 CVE-2020-28848
MISC
wuzhicms — wuzhicms An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php. 2023-08-11 8.8 CVE-2020-36037
MISC
qpdf_project — qpdf An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf. 2023-08-11 8.8 CVE-2021-25786
MISC
pearadmin — pear_admin_think SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php. 2023-08-11 8.8 CVE-2021-29378
MISC
apple — iphone_os The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution. 2023-08-14 8.8 CVE-2022-48503
MISC
MISC
MISC
MISC
MISC
google — android In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. 2023-08-14 8.8 CVE-2023-21273
MISC
MISC
apple — macos A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution. 2023-08-14 8.8 CVE-2023-28198
MISC
MISC
intel(r) — ai_hackathon Uncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user to potentially enable escalation of privilege via network access. 2023-08-11 8.8 CVE-2023-28380
MISC
tigergraph — tigergraph_enterprise An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform installs a full development toolchain within every TigerGraph deployment. An attacker is able to compile new executables on each Tigergraph system and modify system and Tigergraph binaries. 2023-08-15 8.8 CVE-2023-28479
MISC
apple — macos A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution. 2023-08-14 8.8 CVE-2023-32358
MISC
MISC
zyxel — nbg6604 A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request. 2023-08-14 8.8 CVE-2023-33013
MISC
postgresql — postgresql IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:…@ inside a quoting construct (dollar quoting, ”, or “”). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. 2023-08-11 8.8 CVE-2023-39417
MISC
MISC
MISC
jenkins — jenkins A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job. 2023-08-16 8.8 CVE-2023-40341
MISC
MISC
wordpress — wordpress The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the ‘wpdmpp_update_profile’ function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the ‘profile[role]’ parameter during a profile update. 2023-08-12 8.8 CVE-2023-4293
MISC
MISC
MISC
wordpress — wordpress The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the ‘notify_ping_remote’ AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This was partially patched in version 1.2.12 and fully patched in version 1.2.13. 2023-08-16 8.5 CVE-2023-3958
MISC
MISC
MISC
MISC
red_lion_europe — mbnet A vulnerability in Red Lion Europe mbNET/mbNET.rokey and Helmholz REX 200 and REX 250 devices with firmware lower 7.3.2 allows an authenticated remote attacker to store an arbitrary JavaScript payload on the diagnosis page of the device. That page is loaded immediately after login into the device and runs the stored payload, allowing the attacker to read and write browser data and reduce system performance. 2023-08-17 8.3 CVE-2023-34412
MISC
MISC
intel(r) — celeron_j6413_firmware Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access. 2023-08-11 8 CVE-2022-44611
MISC
rockcarry — ffjpeg Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN. 2023-08-11 7.8 CVE-2020-24222
MISC
apple — macos An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted font may lead to arbitrary code execution. 2023-08-14 7.8 CVE-2020-36615
MISC
xnview — xnview Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file. 2023-08-11 7.8 CVE-2021-28427
MISC
xnview — xnview Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file. 2023-08-11 7.8 CVE-2021-28835
MISC
CONFIRM
intel(r) — oneapi_math_kernel_library Uncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access. 2023-08-11 7.8 CVE-2022-25864
MISC
intel(r) — dynamic_tuning_technology Improper access control in the Intel DTT Software before version 8.7.10400.15482 may allow an authenticated user to potentially enable escalation of privilege via local access. 2023-08-11 7.8 CVE-2022-29470
MISC
intel(r)– multiple_products Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access. 2023-08-11 7.8 CVE-2022-38076
MISC
intel(r) — rapid_storage_technology Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may allow an authenticated user to potentially enable escalation of privilege via local access. 2023-08-11 7.8 CVE-2022-43456
MISC
apple — mac_os_x A type confusion issue was addressed with improved state handling. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to execute arbitrary code with kernel privileges. 2023-08-14 7.8 CVE-2022-46706
MISC
MISC
MISC
google — android In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. 2023-08-14 7.8 CVE-2023-21229
MISC
google — android In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected activity due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. 2023-08-14 7.8 CVE-2023-21231
MISC
google — android In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to

Discover more from #News247WorldPress

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading