Red Hat Enterprise Linux: An updated redhat-certification and redhat-certification-cloud package that
fixes several bugs and adds various enhancements is now available for Red Hat
Enterprise Linux 6 and Red Hat Enterprise Linux 7.
Monthly Archives: July 2016
Perixx Computer PERIDUO-710W Keystroke Injection
Perixx Computer PERIDUO-710W suffers from cryptographic issues and keystroke injection vulnerabilities.
Perixx Computer PERIDUO-710W Insufficient Protections
Perixx Computer PERIDUO-710W suffers from insufficient protection of code (firmware) and data (cryptographic key).
Perixx Computer PERIDUO-710W Crypto Issues / Replay Attacks
Perixx Computer PERIDUO-710W suffers from cryptographic issues and replay attack vulnerabilities.
Threatpost News Wrap, July 29, 2016
Mike Mimoso and Chris Brook discuss the news of the week, including a wireless keyboard vulnerability – KeySniffer, NIST’s statement on 2FA, a LastPass remote compromise bug, and a new Tor paper.
Logitech K520 Crypto Issues / Replay Attacks
Logitech K520 keyboards suffer form cryptographic issues and insufficient protection against replay attacks.
Vicon Network Camera Authentication Bypass
Vicon Network Cameras suffer from an authentication bypass vulnerability.
Barracuda Web Application Firewall 8.0.1.008 Post Auth Root
This Metasploit module exploits a remote command execution vulnerability in the Barracuda Web Application Firewall firmware versions 8.0.1.008 (2016-03-22) and below by exploiting a vulnerability in the web administration interface. By sending a specially crafted request it’s possible to inject system commands while escalating to root do to relaxed sudo configuration on the local machine.
CHERRY B.UNLIMITED AES JD-0400EU-2/01 Keystroke Injection
CHERRY B.UNLIMITED AES version JD-0400EU-2/01 suffers from cryptographic issues and keystroke injection vulnerabilities.
Intel Crosswalk Project Man-In-The-Middle
The Intel Crosswalk Project library for cross-platform mobile development did not properly handle SSL errors. This behavior could subject applications developed using this library to SSL MITM attacks.