<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Fabian Ullrich on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/fabian-ullrich/</link>
    <description>Recent content in Fabian Ullrich on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 10 Aug 2022 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/fabian-ullrich/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Whitepaper Endpoint Management &amp;amp; Monitoring Solutions Released</title>
      <link>https://insinuator.net/2022/08/whitepaper-endpoint-management-amp-monitoring-solutions-released/</link>
      <pubDate>Wed, 10 Aug 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/08/whitepaper-endpoint-management-amp-monitoring-solutions-released/</guid>
      <description>&lt;p&gt;Over the course of the last 2 years we performed vulnerability research on&#xA;several Endpoint Management &amp;amp; Monitoring Solutions. The results were already&#xA;partially presented in security advisories which were published on this blog&#xA;during the last two years. The advisories can be found here:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/&#34;&gt;Ivanti DSM Suite&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/&#34;&gt;Solarwinds N-Central&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2020/07/security-advisories-for-nagios-xi/&#34;&gt;Nagios XI&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/&#34;&gt;Broadcom Automic Automation (UC4)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;We also recently presented the results on&#xA;&lt;a href=&#34;https://troopers.de/troopers22/agenda/tr22-1088-a-vulnerability-analysis-of-endpoint-management-monitoring-solutions/&#34;&gt;Troopers 2022&lt;/a&gt;.&#xA;Now the results have been published in a more in-depth manner in the form of a&#xA;technical whitepaper. The whitepaper can be found&#xA;&lt;a href=&#34;https://ernw.de/en/whitepapers/issue-72.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Broadcom Automic Automation (UC4)</title>
      <link>https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/</link>
      <pubDate>Thu, 09 Jun 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/</guid>
      <description>&lt;h2 id=&#34;updated-on-200622-with-cves-and-link-to-broadcom-security-notice&#34;&gt;Updated on 20.06.22 with CVEs and link to Broadcom Security Notice.&lt;/h2&gt;&#xA;&lt;p&gt;In April 2021 we reported seven vulnerabilities in Broadcom Automic Automation&#xA;(UC4) 12.3.5+hf.3. CVE IDs were assigned on 16.06.22, the corresponding Broadcom&#xA;Security Notice can be found&#xA;&lt;a href=&#34;https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/20629&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerabilities have been found in the course of a research project, in&#xA;which we analyzed the security of multiple Endpoint Management solutions.&#xA;Similar vulnerabilities have been found in other solutions as we pointed out in&#xA;previous posts about the&#xA;&lt;a href=&#34;https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/&#34;&gt;Ivanti DSM Suite&lt;/a&gt;,&#xA;&lt;a href=&#34;https://insinuator.net/2020/07/security-advisories-for-nagios-xi/&#34;&gt;Nagios XI&lt;/a&gt;,&#xA;and&#xA;&lt;a href=&#34;https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/&#34;&gt;Solarwinds N-Central&lt;/a&gt;. &#xA;The outcome of the research project will be published as a whitepaper and a&#xA;conference talk at&#xA;&lt;a href=&#34;https://troopers.de/troopers22/talks/brzgam/&#34;&gt;Troopers 2022&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for SolarWinds N-Central</title>
      <link>https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/</link>
      <pubDate>Thu, 10 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/</guid>
      <description>&lt;p&gt;In August 2020 we reported six vulnerabilities in SolarWinds N-Central 12.3.0.670 to the vendor.&lt;/p&gt;&#xA;&lt;p&gt;The following CVE IDs were assigned to the issues :&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;CVE-2020-25617: RCE in N-Central Administration Console (AdvancedScripts Endpoint)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25618: Local Privilege Escalation from nable User to root (N-Central Backend Server)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25619: Access to Internal Services through SSH Port Forwarding (N-Central Backend Server)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25620: SolarWinds Support Account with Default Credentials&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25621: Local Database does not require Authentication (N-Central Backend Server)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25622: CSRF in N-Central Administration Console (AdvancedScripts Endpoint)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The vulnerabilities have been found in the course of an extensive research project, in which we analyze the security of multiple Unified Endpoint Management (UEM) solutions. Similar vulnerabilities have been found in other solutions as we pointed out in previous posts about the &lt;a href=&#34;https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/&#34;&gt;Ivanti DSM Suite&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2020/07/security-advisories-for-nagios-xi/&#34;&gt;Nagios XI&lt;/a&gt;. The final outcome of the research project will be published as a whitepaper and possibly conference talk as soon as the project including all disclosure processes concludes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Nagios XI</title>
      <link>https://insinuator.net/2020/07/security-advisories-for-nagios-xi/</link>
      <pubDate>Thu, 30 Jul 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/07/security-advisories-for-nagios-xi/</guid>
      <description>&lt;p&gt;In June 2020 we reported three vulnerabilities in Nagios XI 5.7.1 to the vendor.&lt;br&gt;&#xA;The following CVE IDs were assigned to the issues :&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt; CVE-2020-15901: Command Injection in Nagios XI web interface (RCE)&lt;/li&gt;&#xA;&lt;li&gt; CVE-2020-15902: Cross Site Scripting (XSS)&lt;/li&gt;&#xA;&lt;li&gt; CVE-2020-15903: Reserved, details will be given on vendor fix&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;CVE-2020-15901 and CVE-2020-15902 have meanwhile been fixed in version 5.7.2 according to the changelog on the Nagios website (&lt;a href=&#34;https://www.nagios.com/downloads/nagios-xi/change-log/)&#34;&gt;https://www.nagios.com/downloads/nagios-xi/change-log/)&lt;/a&gt;. CVE-2020-15903 is currently being worked on by the vendor and will probably be fixed in the near future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Ivanti DSM Suite</title>
      <link>https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/</link>
      <pubDate>Tue, 23 Jun 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/</guid>
      <description>&lt;p&gt;From the end of 2019 on, we reported two critical vulnerabilities in the Ivanti DSM Suite to the vendor. The following CVE IDs were assigned to the issues (but note that they have a status of RESERVED, i.e. titles and descriptions may change in the future):&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;CVE-2020-12441: Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-13793: Unsafe storage of AD credentials in Ivanti DSM netinst 5.1&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The vulnerabilities have meanwhile been fixed and an updated software version can be downloaded &lt;a href=&#34;http://forums.ivanti.com/s/article/Ivanti-DSM-Download-Center&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
