In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
End of software support for 7260X and 7320X series
Date: June 4th, 2024 Products Affected: DCS-7260X Series DCS-7260QX-64 DCS-7260CX-64 DCS-7060CX-32S-D (SSD Model only) DCS-7320X Series DCS-7324X-FM DCS-7328X-FM DCS-7320X-32C Description: This is to notify Arista Networks customers that Arista EOS...
The "Persistent Remote Code Execution Vulnerability" lets attackers execute code persistently on Zyxel devices by injecting malicious code into configuration backups. This code is restored upon reboot, granting lasting access.
The "Local Privilege Escalation Vulnerability" lets attackers escalate their privileges to root on Zyxel devices by exploiting a flaw in the file_upload-cgi endpoint.
The "Python Code Injection Vulnerability" allows attackers to execute arbitrary Python code on Zyxel devices by sending a crafted request to the simZysh endpoint, bypassing authentication and filters.
The "Privilege Escalation and Information Disclosure Vulnerability" allows attackers to escalate privileges and gain admin access on Zyxel devices by sending a crafted request to access session tokens.
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades.