CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed)

CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed) https://ift.tt/2zlAxGL On April 9, 2022, ManageEngine fixed CVE-2022-28810 with the release of ADSelfService Plus Build 6122. The vulnerability allowed the admin user to execute arbitrary operating system commands and potentially allowed partially authenticated Active Directory users to execute arbitrary operating system commands via the password reset functionality. […]

Cisco Releases Security Updates for Multiple Products

Cisco Releases Security Updates for Multiple Products https://ift.tt/g9v1NKn Original release date: April 14, 2022 Cisco has released security updates to address vulnerabilities in multiple Cisco products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Cisco Security Advisories page and apply the […]

Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability

Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability https://ift.tt/Stu3RFU There are workarounds that addresses this vulnerability. Choose one of the following based on the environment: Option 1: No Macfilters in the Environment Customers who do not use macfilters can reset the macfilter radius compatibility mode to the default value using the following CLI command: […]

Microsoft Releases April 2022 Security Updates

Microsoft Releases April 2022 Security Updates https://ift.tt/TbZHa0n Original release date: April 12, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s April 2022 Security Update Summary and Deployment Information and apply […]