-
CVE-2017-12163 samba: server memory information leak over SMB1
CVE ID CVE-2017-12163 DESCRIPTION An information leak flaw was found in the way SMB1 protocol was implemented by Samba. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.…
-
CVE-2017-7805 nss: Potential use-after-free in TLS 1.2 server
CVE ID CVE-2017-7805 DESCRIPTION A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running…
-
CVE-2017-6464 ntp: Denial of Service via malformed config
CVE ID CVE-2017-6464 DESCRIPTION A vulnerability was discovered in the NTP server's parsing of configuration directives. A remote, authenticated attacker could cause ntpd to crash by sending a crafted message. CVSS3 Base Score 5.3 Related CVEs: CVE-2017-6463, CVE-2017-6462 RESOLUTION Fixed in latest Unitrends security…
-
CVE-2018-3646 kernel: L1 Terminal Fault: VMM
CVE ID CVE-2018-3646 DESCRIPTION Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis. 7.1 High…
-
CVE-1999-0505: Microsoft Windows SMB Guest Account User Access
SUMMARY A guest user can access an SMB share CVE ID CVE-1999-0505 DESCRIPTION Microsoft Windows SMB Guest Account User Access A Windows NT domain user or administrator account has a guessable password. The remote host is running one of the Microsoft Windows operating systems or the SAMBA daemon. It was possible to log into…
-
CVE-2015-5600: openssh: MaxAuthTries limit bypass
CVE ID CVE-2015-5600 DESCRIPTION It was discovered that the OpenSSH sshd daemon did not check the list of keyboard-interactive authentication methods for duplicates. A remote attacker could use this flaw to bypass the MaxAuthTries limit, making it easier to perform password guessing attacks. RESOLUTION Unitrends Risk…
-
CVE-2017-7283: Unitrends RCE in restore.php filenames
CVE ID CVE-2017-7283 DESCRIPTION An RCE issue in api/includes/restore.php allowed a remote command execution to be injected when specifying filenames manually. RESOLUTION Unitrends Risk Assessment: None Resolved with latest security update as of 04/14/2017. LINK TO ADVISORIES *…
-
CVE-2017-7281: Unitrends unrestricted report file upload
CVE ID CVE-2017-7281 DESCRIPTION An issue in recoveryconsole/bpl/reports.php allowed a remote user to write arbitrary data to a report file and subsequently execute the file as a php script. RESOLUTION Unitrends Risk Assessment: None. Resolved with latest security update as of 04/17/2017. LINK TO ADVISORIES *…
-
CVE-2017-7284: Unitrends forced password change in users.php
CVE ID CVE-2017-7284 DESCRIPTION An issue in api/includes/users.php allowed a remote user to force a password change on the system without proper credentials. RESOLUTION Unitrends Risk Assessment: None Resolved with latest security update as of 04/14/2017. LINK TO ADVISORIES *…
-
CVE-2017-7279: Unitrends user privilege escalation
CVE ID CVE-2017-7279 DESCRIPTION An issue with stale tokens allowed an existing lower-privileged user to escalate itself to root. RESOLUTION Unitrends Risk Assessment: None. Resolved with release 9.2.0 and latest security update as of 04/14/2017. LINK TO ADVISORIES *…