WECON LeviStudioU Stack-based and Heap-based Buffer Overflow Vulnerabilities

August 14, 2018 | NSFOCUS

According to a report with NCCIC on August 13, two vulnerabilities were found in WECON LeviStudioU. They are stack-based buffer overflow vulnerability (CVE-2018-10602) and heap-based buffer overflow vulnerability (CVE-2018-10606). NSFOCUS security team and Ghirmay Desta worked with Mat Powell of Trend Micro’s Zero Day Initiative to report these vulnerabilities to NCCIC. Successful exploitation of these […]

Multiple Vulnerabilities Disclosed in Samsung SmartThings Hub

August 14, 2018 | NSFOCUS

Talos published multiple vulnerabilities related to Samsung SmartThings Hub recently including many critical vulnerabilities such as demand injection and remote code execution. CVSS v3 base score of 9.9 was assigned to many of these vulnerabilities. For details, please refer to: https://www.talosintelligence.com/vulnerability_reports/#disclosed Vulnerability Description Vulnerability CVE ID CVSS Score Samsung SmartThings Hub video-core camera update code execution vulnerabilities […]

NSFOCUS Achieves ISO 20000 Standard

August 13, 2018 | NSFOCUS

SANTA CLARA, Calif., August 13, 2018 – NSFOCUS, a leader in holistic hybrid security solutions, announced today that it has achieved the ISO 20000 service management system standard. This standard ensures that the company has IT best practices in place for internal and external collaboration, information communication, and performance, while also providing next-level customer service […]

Brief Analysis and Solution | Virus Infection Shuts Down TSMC Factories

August 13, 2018 | NSFOCUS

Taiwan Semiconductor Manufacturing Company (TSMC) is the world’s largest dedicated semiconductor and processor manufactor, manufacturing processors and other chips for the world’s largest science and technology companies including Apple, AMD, NVDIA and Qualcomm. In the evening of August 3, 2018, Beijing time, a technician’s improper operation during software installation caused the virus infection in the […]

Davolink DVW-3200N Vulnerability

August 3, 2018 | NSFOCUS

A critical vulnerability in Davolink DVW-3200N was disclosed on July 31. CVE-2018-10618 has been assigned to this vulnerability and the CVSS v3 base score is 9.8. This device generates a weak password hash that is easy to crack, allowing a remote attacker to gain access to the device. Reference: https://ics-cert.us-cert.gov/advisories/ICSA-18-212-01 Affected Versions DVW-3200N version < […]

Weblogic Remote Code Execution Vulnerability

July 31, 2018 | NSFOCUS

  Oracle Critical Patch Update (CPU) Advisory was released on July 17. In this advisory, Oracle addressed a Weblogic deserialization problem (CVE-2018-2628) that disclosed in April but not completely fixed. The new CVE ID for the Weblogic vulnerability this time is CVE-2018-2893. Basic Scores (CVSS Version 3.0 Risk):9.8 You can refer to the technical analysis […]

Cisco Policy Suite Cluster Manager Default Password Vulnerability

July 31, 2018 | NSFOCUS

Cisco released an advisory on July 18 to alert users about a critical vulnerability (CVE-2018-0375) in its Cluster Manager of Cisco Policy Suite. This vulnerability could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credentials. The vulnerability is due to the presence […]

MODX Revolution Remote Code Execution Vulnerability

July 20, 2018 | NSFOCUS

Recently MODX announced two critical vulnerabilities (CVE-2018-1000207) in MODX Revolution 2.6.4 and earlier versions.  A remote attacker could use the vulnerabilities to execute arbitrary code and further to control the website or delete files. Reference: https://forums.modx.com/thread/104040/revolution-2-6-4-and-prior-two-cricital-vulnerabilities-upgrade-mandatory-patch#dis-post-559515 Affected Versions MODX Revolution <= 2.6.4 Unaffected Versions  Modx Revolution >= 2.6.5 Solution Users are advised to upgrade to MODX […]

NSFOCUS Weekly Cybersecurity Report (ID: 201827)

July 18, 2018 | NSFOCUS

(Report ID: 201827)   Internet Threat Status CVE Statistics The number of new CVE IDs increased considerably last week. Threat Review XXE in WeChat Pay Sdk|WeChat leave a backdoor on merchant websites (07-01-2018) A payment security researcher found an XXE vulnerability in the JAVA version SDK. The attacker can build malicious payload towards the notification […]

XXE Vulnerability in WeChat Payment

July 9, 2018 | NSFOCUS

The website Seclists.Org disclosed a vulnerability in WeChat Pay on 3 July 2018. It was found by a payment security researcher, who described that WeChat unintentionally provides an xxe vulnerability in the JAVA version SDK when merchants provide a notification URL to accept asynchronous payment results. The attacker can build malicious payload towards the notification […]

Search

Subscribe to the NSFOCUS Blog