Critical Vulnerability Detected via Qualys Vulnerability Management Cloud offering and Qualys FreeScan Service
September 30, 2014
PRESS RELEASE
REDWOOD CITY, Calif. –– Sept. 29, 2014 –– Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of cloud security and compliance solutions, today announced that its Qualys Vulnerability Management (VM) cloud service detects the GNU Bash Shellshock (CVE-2014-6271) vulnerability.
Qualys customers can detect the Bash bug by scanning with the Qualys Vulnerability Management (VM) cloud service as QID 122693 and 13038. This means that Qualys customers can get reports detailing their enterprise-wide exposure whenever they next scan their assets, which allows them to get visibility into the impact in their organization and efficiently track the remediation speed of the issue.
Additionally, a vulnerability check for Shellshock is included in Qualys Freescan, which allows any organization to verify the security status of an Internet facing server.
“Bash allows attackers to specify arbitrary commands to execute by formatting an environment variable in a specific way. Given that the flaw has been around for more than10 years, almost all Linux and Unix machines running will be vulnerable and this could have a bigger impact than Heartbleed which we saw earlier this year,” said Wolfgang Kandek, Chief Technical Officer for Qualys, Inc.
For more information on Bash Shellshock, follow the conversation on our Laws of Vulnerabilities blog.
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024