Chirp Systems Chirp Access

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 9.1
  • ATTENTION: Exploitable remotely/low attack complexity
  • Vendor: Chirp Systems
  • Equipment: Chirp Access
  • Vulnerability: Use of Hard-coded Credentials

2. RISK EVALUATION

Successful exploitation of this vulnerability could allow an attacker to take control and gain unrestricted physical access to systems using the affected product.

3. TECHNICAL DETAILS

Read more Chirp Systems Chirp Access

Cisco AppDynamics Controller Path Traversal Vulnerability

A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to access sensitive data on an affected device.

Read more Cisco AppDynamics Controller Path Traversal Vulnerability

(0Day) Ashlar-Vellum Cobalt STP File Parsing Type Confusion Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Read more (0Day) Ashlar-Vellum Cobalt STP File Parsing Type Confusion Remote Code Execution Vulnerability

cURL and libcurl Vulnerability Affecting Cisco Products: October 2023

On October 11, 2023, cURL released Version 8.4.0 of the cURL utility and the libcurl library. This release addressed two security vulnerabilities: 

  • CVE-2023-38545 – High Security Impact Rating (SIR)
  • CVE-2023-38546 – Low SIR

This advisory covers CVE-2023-38545 only. For more information about this vulnerability, see the cURL advisory

This advisory is available at the following link: 

Security Impact Rating: High

CVE: CVE-2023-38545

Nice Linear eMerge E3-Series

1. EXECUTIVE SUMMARY

  • CVSS v3 10.0
  • ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
  • Vendor: Nice
  • Equipment: Linear eMerge E3-Series
  • Vulnerabilities: Path traversal, Cross-site scripting, OS command injection, Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Exposure of Sensitive Information to an Authorized Actor, Insufficiently Protected Credentials, Use of Hard-coded Credentials, Cross-site Request Forgery, Out-of-bounds Write
Read more Nice Linear eMerge E3-Series

Homelab

HP ProLiant MicroServer Gen8

Some time ago I wrote about a home server. This time it is about my home lab. When choosing a server, I looked at size, capacity and power consumption. And I ended up choosing the HP ProLiant MicroServer Gen8. I did some quick research and it turned out that the best I could choose was the Xeon 1265L-V2 processor (best power to TDP ratio) and 16Gb ECC RAM. To this I added a total of four Seagate ST2000VM003 3.5″ drives, each with a capacity of 2TB.

This HP ProLiant MicroServer Gen8 is a powerful and reliable option for those who need a microtower server. Featuring an Intel Xeon E3-1265L v2 CPU, 4 cores, 8 threads, 2.5GHz base and 3.5GHz boost and 16GB ECC DDR3 RAM (maximum possible). The operating system is installed on a Kingston A400 SSD 2.5″ SATA 960GB (SA400S37/960G) for agility and performance.

Read more Homelab

Users in EU will have a choice

Google has just announced a change for users in Europe that will allow them to decide exactly how much data sharing is right for them. The new policy, which the company says is in response to the EU’s Digital Markets Act (DMA), allows users to opt out of data sharing for all, some or none of Google’s selected services. The services listed include YouTube, search, advertising services, Google Play, Chrome, Google Shopping and Google Maps. However, the policy is not airtight – Google will still share user information when necessary to perform a task (for example, when you pay for a purchase on Google Shopping using Google Pay), to comply with the law, to prevent fraud or to protect against abuse.

Read more Users in EU will have a choice

Nextcloud wins the Acteurs du Libre European Award 2023

Nextcloud has won the European Award of the Acteurs du Libre contest! This is a huge recognition for the community, the Nextcloud team, and the visionary leaders behind the project.

What is the Acteurs du Libre contest?

The Acteurs du Libre contest is part of the Open Source Experience event, which celebrates the achievements of Free Software companies, entrepreneurs, projects and associations. The contest awards six prizes every year, each honoring a different aspect of FOSS development, management or implementation: the Committed Public Service Award, the European Award in collaboration with APELL, the Business Development Award, the Best Open Source Strategy Award, the Open and Ethical Digital Award, and the Jury’s Special Award.

Read more Nextcloud wins the Acteurs du Libre European Award 2023

Comparison of lightweight Linux distros

DietPi

I started to look for a replacement for my DietPi (I’m using it as my everyday OS). It’s installed as a VM on the Proxmox server. It’s fast, it’s nice, it reliable, but I want to change something 🙂

Also, one of the reasons why I selected DietPi was the Home Assistant core. Or I should say – the way it’s installed. And how most of the software is managed in DietPi. It uses DietPi-Software, which allows you to quickly and easily install popular software “ready to run” and this software is already optimized for your system. Only the software you need is installed.

What is DietPi? DietPi is an extremely lightweight Debian OS, highly optimized for minimal CPU and RAM resource usage, ensuring your SBC always runs at its maximum potential. It has a lots of different flavours, so you may install it on Raspberry Pi, Odroid, Pine64, Radxa, Allo, NanoPi, OrangePi, but also on standard PC and as a VM (I’m sure I didn’t mention all of them, but those I remember :P)

Read more Comparison of lightweight Linux distros