article thumbnail

CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP

Tenable

A critical authentication bypass vulnerability in F5’s BIG-IP could allow remote, unauthenticated attackers to execute system commands. At the time their initial blog post was released, no CVE identifier was provided, however, Praetorian noted that additional technical details would be released once a patch was available from F5.

article thumbnail

CVE-2022-27510: Critical Citrix ADC and Gateway Authentication Bypass Vulnerability

Tenable

CVE-2022-27510: Critical Citrix ADC and Gateway Authentication Bypass Vulnerability Citrix publishes an advisory to address multiple flaws in its ADC and Gateway products, including a critical vulnerability. CVE-2022-27510. Citrix ADC and Gateway Authentication Bypass Vulnerability. CVE-2022-27513. CVE-2022-27516.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CVE-2022-37958: FAQ for Critical Microsoft SPNEGO NEGOEX Vulnerability

Tenable

CVE-2022-37958: FAQ for Critical Microsoft SPNEGO NEGOEX Vulnerability Microsoft recently reclassified a vulnerability in SPNEGO NEGOEX, originally patched in September, after a security researcher discovered that it can lead to remote code execution. Frequently Asked Questions (FAQ) about CVE-2022-37958. What is CVE-2022-37958?

Windows 98
article thumbnail

CVE-2022-22972: VMware Patches Additional Workspace ONE Access Vulnerabilities (VMSA-2022-0014)

Tenable

On May 18, VMware published an advisory ( VMSA-2022-0014 ) to address two vulnerabilities across several VMware products: CVE. CVE-2022-22972. Authentication Bypass Vulnerability. CVE-2022-22973. CVE-2022-22973 is a local privilege escalation vulnerability in the VMware Workspace ONE Access and Identity Manager.

article thumbnail

Microsoft’s June 2022 Patch Tuesday Addresses 55 CVEs (CVE-2022-30190)

Tenable

Microsoft addresses 55 CVEs in its June 2022 Patch Tuesday release, including three critical flaws. Microsoft patched 55 CVEs in its June 2022 Patch Tuesday release, with three rated as critical, 52 rated as important. CVE-2022-30136 | Windows Network File System Remote Code Execution Vulnerability. CVE-2022-30139.

Windows 97
article thumbnail

CVE-2022-27518: Unauthenticated RCE in Citrix ADC and Gateway

Tenable

CVE-2022-27518: Unauthenticated RCE in Citrix Gateway and Citrix ADC Citrix has patched a critical remote code execution vulnerability in its ADC and Gateway products. Both the advisory and blog post note that targeted attacks have been observed in the wild and customers should patch this vulnerability immediately. Background.

article thumbnail

CVE-2022-41040 and CVE-2022-41082: ProxyShell Variant Exploited in the Wild

Tenable

On September 28, GTSC Cybersecurity Technology Company Limited published a blog post (English translation published later ) regarding their discovery of two zero-day vulnerabilities in Microsoft Exchange Server. Exploitation of CVE-2022-41040 could allow an attacker to exploit CVE-2022-41082. orange_8361) September 29, 2022.