About marc

This author has not yet filled in any details.
So far marc has created 41 blog entries.

Cisco Firepower 4100 Series, Firepower 9300 SA, and UCS 6300 Series Vulnerabilities

A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Cisco Firepower 4100 Series, Firepower 9300 SA, and UCS 6300 Series Vulnerabilities2023-08-30T13:42:53-04:00

Citrix ADC and Citrix Gateway Security Bulletin for CVE-2023-3519, CVE-2023-3466, CVE-2023-3467

Multiple vulnerabilities have been discovered in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Citrix released an advisory tagged CTX561482

Citrix ADC and Citrix Gateway Security Bulletin for CVE-2023-3519, CVE-2023-3466, CVE-2023-34672023-07-19T10:58:10-04:00

Unpatched or Unsupported Microsoft Exchange Servers Can Expect an SMTP 450 Error

On Monday, March 24th, 2023, Microsoft announced that it is enabling a transport-based enforcement system in Exchange Online serving three functions: reporting, throttling, and blocking.

Unpatched or Unsupported Microsoft Exchange Servers Can Expect an SMTP 450 Error2023-04-04T09:32:32-04:00

Citrix NetScaler 12.1 Goes End-of-Life (EOL)

May 30th, 2023, marks the end-of-life (EOL) for Citrix NetScaler firmware 12.1. EOL refers to the termination of support and updates for Citrix NetScaler 12.1. This means that after the May 30th date, Citrix will no longer provide technical support, security updates, or bug fixes for NetScaler 12.1. Users’ Citrix NetScaler devices will no longer receive critical security updates or technical support, leaving their devices vulnerable to potential security threats and software bugs. This can result in reduced system performance, reliability, and compatibility issues with newer software and hardware.

Citrix NetScaler 12.1 Goes End-of-Life (EOL)2023-05-02T11:14:45-04:00

ICYMI: Recap of Last Week’s Security Alerts – week of March 12, 2023

ICYMI: Recap of Last Week’s Security Alerts – week of March 12, 2023 VMware Cloud Foundation remote code execution vulnerability via XStream (CVE-2021-39144) CISA identified VMware products to the CVE-2021-39144 vulnerability in its Known Exploited Vulnerabilities (KEV) catalog following confirmation from VMware that this bug is being exploited since December 2022. Veeam Backup & Replication Vulnerability (CVE-2023-27532) A vulnerability been found in Veeam Backup & Replication that enables an unauthenticated user to request encrypted credentials, [...]

ICYMI: Recap of Last Week’s Security Alerts – week of March 12, 20232023-03-23T13:27:39-04:00

Microsoft Outlook Privilege Elevation Vulnerability (CVE-2023-23397)

CISA added a zero-day vulnerability affecting Microsoft Outlook that is actively exploited in the wild. Microsoft has released a patch for the vulnerability as part of their March 2023 Patch Tuesday.

Microsoft Outlook Privilege Elevation Vulnerability (CVE-2023-23397)2023-04-12T12:39:15-04:00

VMware Cloud Foundation remote code execution vulnerability via XStream (CVE-2021-39144)

CISA identified VMware products to the CVE-2021-39144 vulnerability in its Known Exploited Vulnerabilities (KEV) catalog following confirmation from VMware that this bug is being exploited since December 2022.

VMware Cloud Foundation remote code execution vulnerability via XStream (CVE-2021-39144)2023-04-04T11:30:07-04:00