mitigation

November 28, 2024

Upgrading OpenSSL to Address Vulnerabilities

Subject: Security Update Guidance: Upgrading OpenSSL to Address Vulnerabilities Overview: OpenSSL, a widely used open-source cryptographic library that provides secure communication over networks, frequently receives updates […]
November 28, 2024

Mitigation Instructions for Redis Server Unprotected by Password Authentication

Subject: Redis Server Unprotected by Password Authentication Tech Stack: Redis Date(s) Issued: Criticality: Overview The critical misconfiguration concerns a Redis server that is not protected by password authentication. […]
November 26, 2024

Mitigation Instructions for CVE-2010-3972

SUBJECT: CVE-2010-3972 Heap-based buffer overflow TECH STACK: Microsoft FTP Service 7.0 and 7.5 DATE(S) ISSUED: 12/23/2010 NVD Last Modified: 02/05/2021 CRITICALITY: CRITICAL OVERVIEW: CVE-2010-3972 is a serious security vulnerability that […]
November 26, 2024

Mitigation Instructions for CVE-2020-15778

SUBJECT: CVE-2020-15778 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) TECH STACK: OpenSSH  DATE(S) ISSUED: 07/24/2020 NVD Last Modified: 02/24/2023 CRITICALITY: HIGH OVERVIEW: CVE-2020-15778 is […]