Home

2021年05月の脆弱性

誤りがあった場合はTwitterに報告をお願いします。-> Twitter《Har-sia》

今月話題になった脆弱性まとめ

CVE-2020-11292


Highest Score:41 (2021/05/07)

脆弱性情報:Har-sia CVE-2020-11292


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-21551

Description from NVD

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

Information Acquisition Date:2021/06/01
CVSS 2.0: 4.6 MEDIUM CVSS 3.x: 7.8 HIGH

Highest Score:145 (2021/05/05)

脆弱性情報:Har-sia CVE-2021-21551


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-21985

Description from NVD

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Information Acquisition Date:2021/06/01
CVSS 2.0: 0.0 None CVSS 3.x: 0.0 None

Highest Score:89 (2021/05/26)

脆弱性情報:Har-sia CVE-2021-21985


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-22893

Description from NVD

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

Information Acquisition Date:2021/06/01
CVSS 2.0: 7.5 HIGH CVSS 3.x: 10.0 CRITICAL

Description from Forti

Security Vulnerability CVE-2021-22893 for Pulse Secure

Information Acquisition Date:2021/05/05

Affected Products

Impact

Recommended Actions

References


Highest Score:180 (2021/04/21)

脆弱性情報:Har-sia CVE-2021-22893


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-28550


Highest Score:38 (2021/05/12)

脆弱性情報:Har-sia CVE-2021-28550


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-30747


Highest Score:44 (2021/05/31)

脆弱性情報:Har-sia CVE-2021-30747


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-31166

Description from NVD

HTTP Protocol Stack Remote Code Execution Vulnerability

Information Acquisition Date:2021/06/01
CVSS 2.0: 7.5 HIGH CVSS 3.x: 9.8 CRITICAL
This vulnerability may involve a PoC.

Highest Score:82 (2021/05/18)

脆弱性情報:Har-sia CVE-2021-31166


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-31876

Description from NVD

Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with nSequence = 0xff_ff_ff_ff, spending an unconfirmed parent with nSequence <= 0xff_ff_ff_fd, should be replaceable because there is inherited signaling by the child transaction. However, the actual PreChecks implementation does not enforce this. Instead, mempool rejects the replacement attempt of the unconfirmed child transaction.

Information Acquisition Date:2021/06/01
CVSS 2.0: 6.4 MEDIUM CVSS 3.x: 6.5 MEDIUM

Highest Score:39 (2021/05/22)

脆弱性情報:Har-sia CVE-2021-31876


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-32471

Description from NVD

Insufficient input validation in the Marvin Minsky 1967 implementation of the Universal Turing Machine allows program users to execute arbitrary code via crafted data. For example, a tape head may have an unexpected location after the processing of input composed of As and Bs (instead of 0s and 1s). NOTE: the discoverer states "this vulnerability has no real-world implications."

Information Acquisition Date:2021/06/01
CVSS 2.0: 7.2 HIGH CVSS 3.x: 7.8 HIGH

Highest Score:40 (2021/05/11)

脆弱性情報:Har-sia CVE-2021-32471


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


計9件

Tweet