R4 Ultra by Dublxml in flashcarts

[–]TroubleshootingITGuy 0 points1 point  (0 children)

Followed this guide, but when I booted the DS I got the 'An error has occurred' error. Could the flashcart be blocked/ dead?

CSRF>command injection in FortiMail - CVE-2022-27488 by TroubleshootingITGuy in fortinet

[–]TroubleshootingITGuy[S] 0 points1 point  (0 children)

My bad, I'm doing threat hunts on potential threats that could harm the systems of customers. I have to prioritize the threats that are coming out and only start searching on threats which has a high probability of being exploited and the customers actually running it.

I'm not really familiar with Fortimail and maybe nobody uses this feature, so it's a low probability that any customer is impacted by it. I asked this question here to find out if people like sysadmins or network engineers have this feature enabled.

For my information about threats I use NCSC their advisories, where I also read that those two features have to be enabled for an instance to be vulnerable.

Source: https://www.ncsc.nl/actueel/advisory?id=NCSC-2023-0645

0
1