In this week's Security Advisory:
Cisco has issued an advisory to address two significant vulnerabilities in its Integrated Management Controller (IMC) that could result in arbitrary code execution with root user privileges. CVE-2024-20295 (CVSS score: 8.8 out of 10) and CVE-2024-20356 (CVSS score: 8.7 out of 10) can allow an authenticated, local attacker to exploit improper input validations through command injections within the controller's command-line interface, enabling them to execute customized commands and elevate their privileges to root access. Of note, proof-of-concepts (POC) for these vulnerabilities have been publicly disclosed and exploitation have been observed in the wild.
More Reading/Information
A zero-day vulnerability was discovered in CrushFTP that could allow an unauthenticated attacker to obtain sensitive system data outside of the virtual file system sandbox. While this vulnerability requires a CrushFTP host to be publicly exposed to the internet, the flaw allows an attacker to bypass authentication and remotely execute malicious code that can exfiltrate client data. The vulnerability is being tracked as CVE-2024-4040 with a critical CVSS rating of 9.8 out of a possible 10.
Of note, exploitation of this flaw has been observed in the wild.
Affected Versions:
More Reading/Information
There were three (3) vulnerabilities discovered in the WordPress plugin, Forminator, which could result in a threat actor executing arbitrary commands and gaining access to unauthorized information. Forminator is a popular form builder tool used by developers to create widgets, polls, surveys and payment forms on their websites. Among the identified issues, CVE-2024-28890 (CVSS score: 9.8 out of 10) is a flaw that can allow an attacker to upload malicious files and execute code to acquire sensitive data.
CVE-2024-31077 (CVSS score: 7.1 out of 10) allows arbitrary commands to execute due to improper input validation in SQL queries. CVE-2024-31857 (CVSS score: 6.1 out of 10) is a cross-site script vulnerability that can allow an attacker to alter site contents of a user's webpage.
Affected Versions:
More Reading/Information
Google Chrome released a security update to fix four (4) vulnerabilities, with one (1) vulnerability given a severity rating of "Critical". These vulnerabilities affect Windows, Mac and Linux.
Oracle released 441 patches in their quarterly update, which fixed vulnerabilities in several of their products. The most severe can lead to remote code execution, which can allow a threat actor to install programs, view, change, or delete information, and potentially gain control of an affected system. It is recommended to update all affected products to their latest version. The full list of affected Oracle products can be found here: https://www.oracle.com/security-alerts/cpuapr2024.html
More Reading/Information
Please review your environment to ensure the above-mentioned issues are patched in a timely manner. It is security best practice to regularly update and/or patch software to the latest versions. The vulnerabilities above highlight the security benefits of limiting deployed software to "vendor-supported versions" only. This dramatically increases the likelihood that new vulnerabilities have a patch issued for them. Likewise, Cybersafe strongly encourages maintaining an inventory of current software in your environment, which helps ensure and inform your patch and vulnerability management program.