Security Notice - Statement On Some AMI MegaRAC BMC Vulnerabilities
2022-12-07 | Security Notices
Eclypsium Research has discovered and reported 3 vulnerabilities(CVE-2022-40259、CVE-2022-40242、CVE-2022-2827) in AMI MegaRAC Baseboard Management Controller (BMC) software. We are referring to these vulnerabilities collectively as BMC&C. The BMC&C vulnerabilities range in severity from Medium to Cri...
Security Notice - Statement On Spring Framework RCE Vulnerability
2022-04-01 | Security Notices
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is ...
Security Notice - Statement On Apache Log4j2 Vulnerability CVE-2021-44228
2021-12-13 | Security Notices
Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when messa...
Security Notice - Statement On Ripple20 Vulnerabilities
2020-06-23 | Security Notices
The JSOF research lab has discovered a series of zero-day vulnerabilities in a widely used low-level TCP/IP software library developed by Treck, Inc. The 19 vulnerabilities, given the name Ripple20, affect hundreds of millions of devices (or more) and include multiple remote code execution vulnerabi...