Zephyrnet Logo

Reddit Attack Defaces Dozens of Channels

Date:

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2020-15058
PUBLISHED: 2020-08-07

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

CVE-2020-15059
PUBLISHED: 2020-08-07

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.

CVE-2020-15060
PUBLISHED: 2020-08-07

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.

CVE-2020-15061
PUBLISHED: 2020-08-07

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.

CVE-2020-15062
PUBLISHED: 2020-08-07

DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

Source: https://www.darkreading.com/attacks-breaches/reddit-attack-defaces-dozens-of-channels/d/d-id/1338614?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple

spot_img

Latest Intelligence

spot_img

Chat with us

Hi there! How can I help you?