Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8581PUBLISHED: 2021-01-19Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.
CVE-2021-20190PUBLISHED: 2021-01-19A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2020-27270PUBLISHED: 2021-01-19SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).
CVE-2020-27272PUBLISHED: 2021-01-19
SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the ...
CVE-2020-27276PUBLISHED: 2021-01-19
SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entities before exchanging keys, which allows unauthenticated, physically prox...
User Rank: Strategist
11/6/2020 | 7:51:06 AM
Has to be managed. Has to be tracked. As it scales it becomes its own dedicated time management problem. Like just about 90% of CND/Cyber Defense certainly great for jobs!
As we slip into Active Dense - an old concept - where is the golden grail of attribution?
Will it lead to self-DOS opportunities of a more sophisticated stripe?