Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-0240PUBLISHED: 2023-01-30
There is a logic error in io_uring's implementation which can be used to trigger a use-after-free vulnerability leading to privilege escalation. In the io_prep_async_work function the assumption that the last io_grab_identity call cannot return false is not true, and in this case the function will u...
CVE-2023-0266PUBLISHED: 2023-01-30
A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_WRITE32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b...
CVE-2022-45788PUBLISHED: 2023-01-30
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxureâ„¢...
CVE-2022-38451PUBLISHED: 2023-01-30A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-42484PUBLISHED: 2023-01-30An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
User Rank: Ninja
6/30/2019 | 3:04:19 PM
I do think this is the future, we need to look into blockchain and how we can enhance our security posture when it relates to Bitcoin. I do think Blockchain can help with areas of the supply chain but that is for another conversation.
T