TrustedSec Tech Brief - Week of September 2, 2024

Опубликовано: 19 Апрель 2026
на канале: TrustedSec
334
8

Welcome to the TrustedSec Tech Brief where Director of Security Intelligence Carlos Perez goes over top security news for the week of September 2.

Chapters:
00:00 Intro
00:13 News
03:30 Vulnerabilities

Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
https://jfrog.com/blog/revival-hijack...
https://github.com/advisories?query=t...
Vulnerabilities:

CVE-2024-20439
Cisco Smart Licensing Utility
CSVSS: 9.8
POC: NO
Exploited: No

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to log in to an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account.

CVE-2024-7261
Zyxel Corporation
Multiple AP and Routers
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

https://www.zyxel.com/global/en/suppo...


CVE: In Progress
Yubico
CVSS: 4.9
POC: Yes
Exploited: No
Description: YubiKey 5 Series, and Security Key Series with firmware prior to 5.7.0 and YubiHSM 2 with firmware prior to 2.4.0. Infineon ECDSA Private Key Recovery, the vulnerability is a moderate one given that specialized equipment is needed, access to the Yubikey or Java Card is needed. It may require the PIN, Fingerprint, username or other security value.

Link: https://www.yubico.com/support/securi...


CVE: CVE-2024-45195
Affected Product: Apache OFBiz (versions below 18.12.16)
CVSS: 7.5
POC: Yes
Exploited: No
Description: Apache OFBiz below version 18.12.16 is vulnerable to unauthenticated remote code execution on Linux and Windows. An attacker with no valid credentials can exploit missing view authorization checks in the web application to execute arbitrary code on the server. This vulnerability is a patch bypass for previous CVEs (CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856).

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-20439
Affected Product: Cisco Smart Licensing Utility
CVSS: 9.8
POC: No
Exploited: No
Description: Allows unauthenticated remote attackers to gain administrative access using a static credential due to an undocumented administrative account.

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-20440
Affected Product: Cisco Smart Licensing Utility
CVSS: 9.8 (Cisco advisory), 7.5 (NVD)
POC: No
Exploited: No
Description: Information disclosure vulnerability caused by overly verbose logging, allowing attackers to retrieve sensitive log files containing credentials.

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-20430
Affected Product: Cisco Meraki Systems Manager Agent for Windows
CVSS: 7.3
POC: No
Exploited: No
Description: Allows authenticated, low-privileged attackers to escalate privileges by exploiting improper handling of directory search paths.

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-40711
Affected Product: Veeam Backup & Replication
CVSS: 9.8
POC: No
Exploited: No
Description: Unauthenticated Remote Code Execution (RCE) vulnerability.

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-38650
Affected Product: Veeam Service Provider Console
CVSS: 9.9
POC: No
Exploited: No
Description: Allows low-privileged attackers to access the NTLM hash of the service account on the VSPC server.

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-39714
Affected Product: Veeam Service Provider Console
CVSS: 9.9
POC: No
Exploited: No
Description: Permits arbitrary file uploads on VSPC servers, leading to Remote Code Execution (RCE).

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-42024
Affected Product: Veeam ONE
CVSS: 9.1
POC: No
Exploited: No
Description: Enables Remote Code Execution (RCE) for attackers with Veeam ONE Agent service account credentials.

Link: https://nvd.nist.gov/vuln/detail/CVE-...


CVE: CVE-2024-42019
Affected Product: Veeam ONE
CVSS: 9.0
POC: No
Exploited: No
Description: Allows attackers to access the NTLM hash of the Veeam Reporter Service service account, requiring user interaction and data from Veeam Backup & Replication.

Link: https://nvd.nist.gov/vuln/detail/CVE-...