Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-23896PUBLISHED: 2022-06-28Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).
CVE-2022-29519PUBLISHED: 2022-06-28Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware.
CVE-2022-30707PUBLISHED: 2022-06-28
Violation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CENTUM series where LHS4800 is installed (CENTUM CS 3000 and CENTUM CS 3000 Small R3.08.10 to R3.09.00), CENTUM series where CAMS function is used (CENTUM VP, CENTUM VP Small, and CE...
CVE-2022-30997PUBLISHED: 2022-06-28Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware.
CVE-2022-34750PUBLISHED: 2022-06-28
An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thousand characters. Unfortunately, this length is not validated, allowing much larger lexemes to be created, which introduces various denial-of-service attack vectors within the Wikib...
User Rank: Apprentice
5/25/2017 | 3:54:15 PM
Patching yes is key, but the most important is still Security awarness. How did this worm get in? It was via unwarry email users opening emails and fillowing links or activating attachments that is the entry point of this vulnerability.
The problem is we in the community tend to close the barn door after the horse has run through the house.
We do not need to depend on more tech solutions (Patching exempt).
Time to start serious end user education and start to close down the weekest link.