By michele654 on Wednesday, 01 February 2023
Category: Vulnerabilities

New Vulnerabilities Tuesday 01 February


New Alerts for HPE, VMware, and Cacti.

HPE 

HPE OneView contains a Use After Free vulnerability in Expat. CVSSv3 score of 9.8
More info.

VMware 

vRealize Operations (vROps) contains a CSRF bypass vulnerability. CVSSv3 score of 6.5
More info.

Exploit code is out for the Jan 24 Critical bulletin.
More info.

Cacti 

A command injection vulnerability allows a remote attacker to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. CVSSv3 score of 9.8
More info. And here.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments