Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)
🎯 建议动作: 建议根据原文自行评估
共收录 4 条相关安全情报。
← 返回所有主题Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)
🎯 建议动作: 建议根据原文自行评估
该漏洞影响 Veeam Service Provider Console 组件,允许未经认证的远程攻击者通过发送特制请求触发远程代码执行(RCE)。由于 Veeam Service Provider Console 常用于云服务提供商的备份管理,其暴露在公网的面较大,一旦被利用,攻击者可完全接管控制台服务器,进而横向移动至受保护的备份环境,窃取或破坏数据。目前官方尚未发布安全公告,但鉴于漏洞的严重性(RCE 类型),建议立即实施缓解措施,包括:将控制台置于内部网络并限制来源 IP 访问、启用 Web 应用防火墙规则、密切监控异常日志。厂商预计将在下一个版本中修复该漏洞,请持续关注 Veeam 官方更新。
💡 影响/原因: 该漏洞为无需用户交互的远程代码执行,攻击者可完全控制 Veeam 服务提供商控制台,威胁备份基础设施和客户数据安全。
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
💡 风险点: 原文内容(由于配额限制,未进行深度 LLM 分析)
🎯 建议动作: 建议根据原文自行评估
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)
🎯 建议动作: 建议根据原文自行评估