Overview Recently, NSFOCUS CERT found that Atlassian officially fixed a Jira Service Management Server and Data Center authentication bypass vulnerability (CVE-2023-22501). When write access to user directories and outgoing emails is enabled on a Jira Service Management instance, an unauthenticated remote attacker can gain access to Jira Service Management by...
Categoria: Blog
F5 BIG-IP iControl SOAP Remote Code Execution Vulnerability (CVE-2023-22374) Alert
Overview Recently, NSFOCUS CERT found that the technical details of the F5 BIG-IP arbitrary code execution vulnerability (CVE-2023-22374) were publicly disclosed online. Due to the format string vulnerability in BIG-IP iControl SOAP, a remote attacker with administrator authority can access the iControl SOAP interface through the BIG-IP management port or...
QNAP QTS and QuTS hero SQL Injection Vulnerability (CVE-2022-27596) Notice
Overview On January 31, 2023, NSFOCUS CERT detected that QNAP officially released a QNAP QTS and QuTS hero SQL injection vulnerability (CVE-2022-27596) notice. Due to the flaws in QNAP QTS and QuTS hero, unauthenticated remote attackers can use this vulnerability to inject malicious code on QNAP NAS devices, and ultimately...
NSFOCUS selected in Gartner’s Market Guide™ for Managed Detection and Response Services, China
We are honored to be selected in Gartner® Market Guide™ for Managed Detection and Response Services, China 2022 as a representative vendor with our outstanding integrated security operation services. This is the second time NSFOCUS MDR service has been listed in a report issued by an international research institution after...
NSFOCUS Zero-Trust Anti-DDoS Solution Enhances Protection Capability against C&C and Bot Attacks
Santa Clara, Calif. February 02, 2023 - NSFOCUS, a global provider of intelligent hybrid security solutions, announced today that it has been selected in Forrester’s recently published report, The Forrester Tech Tide™: Zero Trust Threat Prevention, Q4 2022 for its NSFOCUS Anti-DDoS System (ADS). The report presents an in-depth analysis...
Multiple Security Vulnerabilities Alerts of VMware vRealize Log Insight
Overview Recently, NSFOCUS CERT found that VMware has officially fixed multiple security vulnerabilities in VMware vRealize Log Insight. Under default configuration conditions, unauthenticated attackers exploit the following key vulnerabilities in combination, and finally achieve arbitrary code execution with ROOT privileges on the target system. These vulnerabilities have been successfully verified...





