VU#619785: Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP web server vulnerability

Citrix has published a security bulletin that mentions a vulnerability that can be exploited to achieve arbitrary code execution by a remote,unauthenticated attacker. Although the bulletin does not describe details about the vulnerability,the mitigatio… Continue reading VU#619785: Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP web server vulnerability

Posted in Uncategorized

VU#873161: Telos Automated Message Handling System contains multiple vulnerabilities

Telos AMHS is a web-based messaging system that supports DoD and Intelligence Community(IC)security marking requirements. AMHS versions prior to version 4.1.5.5 contain multiple XSS vulnerabilities and also fail to properly restrict access to informati… Continue reading VU#873161: Telos Automated Message Handling System contains multiple vulnerabilities

Posted in Uncategorized

VU#719689: Multiple vulnerabilities found in the Cobham EXPLORER 710 satcom terminal

The Cobham EXPLORER 710 is a portable satellite terminal used to provide satellite telecommunications and internet access. For consistency,“device” mentioned in the following section is defined as the Cobham EXPLORER 710. The affected firmware version … Continue reading VU#719689: Multiple vulnerabilities found in the Cobham EXPLORER 710 satcom terminal

Posted in Uncategorized

VU#672565: Exim fails to properly handle trailing backslashes in string_interpret_escape()

Exim is a message transfer agent(MTA)that can be used on Unix-like operating systems. All versions up to and including 4.92.1 of Exim do not properly handle trailing backslash characters in the string_interpret_escape()function,which is used to process… Continue reading VU#672565: Exim fails to properly handle trailing backslashes in string_interpret_escape()

Posted in Uncategorized

VU#918987: Bluetooth BR/EDR supported devices are vulnerable to key negotiation attacks

Bluetooth is a short-range wireless technology based off of a core specification that defines six different core configurations,including the Bluetooth Basic Rate/Enhanced Data Rate Core Configurations. Bluetooth BR/EDR is used for low-power short-rang… Continue reading VU#918987: Bluetooth BR/EDR supported devices are vulnerable to key negotiation attacks

Posted in Uncategorized