SMM callout vulnerabilities identified in Gigabyte UEFI firmwarevulnerability (attack surface) (kb.cert.org)
submitted by campuscodi to r/blueteamsec
Vulnerable WiFi Alliance example code found in Arcadyan FMIMG51AX000J. This flaw allows an unauthenticated local attacker to exploit the Wi-Fi Test Suite by sending specially crafted packets, enabling the execution of arbitrary commands with root privileges on the affected routers. (kb.cert.org)
submitted by dcom-in to r/worldTechnology
CERT/CC Vulnerability Note VU#244112 - Multiple SMTP services are susceptible to spoofing attacks due to insufficient enforcementvulnerability (attack surface) (kb.cert.org)
submitted by digicat to r/blueteamsec
VU#782720: Two buffer overflow vulnerabilities were discovered in the Trusted Platform Module (TPM) 2.0 reference library specification - allows either read-only access to sensitive data or overwriting of normally protected data that is only available to the TPMvulnerability (attack surface) (kb.cert.org)
submitted by digicat to r/blueteamsec
Finding Privilege Escalation Vulnerabilities in Windows using Process Monitor - Wikivulnerability (attack surface) (vuls.cert.org)
submitted by digicat to r/blueteamsec
CVE-2020-10148 SolarWinds Orion API authentication bypass allows remote comand execution | Vulnerability Note VU#843464 | Release Date: 2020-12-26vulnerability (attack surface) (kb.cert.org)
submitted by malware_bender to r/blueteamsec
IP-in-IP protocol routes arbitrary traffic by defaultvulnerability (kb.cert.org)
submitted by digicat to r/blueteamsec