CVE-2023-20194 - How Authenticated Admins Can Read Any File on Cisco ISE Devices (ERS API Vulnerability)
In June 2023, Cisco disclosed CVE-2023-20194, a serious vulnerability affecting the ERS (External RESTful Services) API in Cisco Identity Services Engine (ISE). This
CVE-2023-39422 - HMAC Token Leak in IRM Next Generation Booking Engine (/irmdata/api/) — How a Client-Side JavaScript Mistake Broke Their Security
---
Introduction
CVE-2023-39422 is a security vulnerability found in the IRM Next Generation booking engine — a solution often used by hotels and travel companies
CVE-2023-39423 - Exploiting SQL Injection in RDPData.dll to Hijack Active Sessions
A serious vulnerability, now tracked as CVE-2023-39423, was found in certain software using the RDPData.dll library. This flaw exposes an API endpoint,
CVE-2023-39421 - How Hardcoded API Keys in RDPWin.dll Expose Sensitive Services
A recently disclosed security vulnerability, CVE-2023-39421, highlights the risks of hardcoded secrets in software used by hotels and resorts worldwide. The issue arises
CVE-2023-36635 - Exploiting Improper Access Control in Fortinet FortiSwitchManager — From Read-Only to Configuration Changes
CVE-2023-36635 is a recently disclosed vulnerability that directly affects Fortinet FortiSwitchManager—an essential piece of software often responsible for the configuration and management
Episode
00:00:00
00:00:00