Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-40480PUBLISHED: 2023-02-08Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.
CVE-2022-45190PUBLISHED: 2023-02-08An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the device.
CVE-2022-45191PUBLISHED: 2023-02-08An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values.
CVE-2022-45192PUBLISHED: 2023-02-08An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request.
CVE-2023-0718PUBLISHED: 2023-02-08
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this ...
User Rank: Apprentice
10/6/2015 | 2:15:06 AM
They keep saying there isn't enough "qaulified" security professionals. What constitutes qaulified? Those that sold their house to get certified, those that can find the ways to study but don't have certifications due to lack of funds?
IF they count only those with certifications as qaulified, they need to find ways so that those of us that really want to get into the field, help in the field can get those without selling our first unborn and grandparents.