Control Gap Vulnerability Roundup: January 14th to January 20th
This week saw the publication of 712 new CVE IDs. Of those, 247 have not yet been assigned official CVSS scores, however, of the ones that were, approximately 21% were of critical severity, 29% were high, 48% were medium, and 2% were low. Listed below are the vulnerabilities that caught our attention:
- Multiple remote code execution vulnerabilities were identified in the universal open-source project Git via a source-code review conducted by X41 D-Sec and the GitLab Security Research Team.
- Two vulnerabilities which could be chained together to achieve unauthenticated remote code execution have been disclosed for multiple models of Cisco Small Business router. The products are end-of-life and Cisco has stated they will not be addressing the vulnerabilities.
- A vulnerability in the Samsung Galaxy App store could allow applications already present on the phone to install any app available through the app store without user permission. The vulnerability does not affect versions of Android 13 or later due to additional security measures implemented on the OS.
- Multiple vulnerabilities were disclosed by CISA for Sewio’s Real-Time Location System including remote code execution. Given the product’s ability to track personnel in real-time, the impact may be much more severe than the assigned CVSS score.