Tag: Critical Flaw

Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical Flaw
News

Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical Flaw

Malevolent entities are probably utilizing publicly accessible proof-of-concept (PoC) exploits for newly discovered security vulnerabilities in Progress Software WhatsUp Gold to carry out opportunistic assaults. The action is reported to have started on August 30, 2024, just five hours after security researcher Sina Kheirkhah of the Summoning Team published a proof of concept for CVE-2024-6670 (CVSS score: 9.8). Sina Kheirkhah is also credited with finding and reporting CVE-2024-6671 (CVSS scores: 9.8). Progress addressed both of the major vulnerabilities in mid-August 2024, which let an unauthorized attacker obtain an encrypted password belonging to a user read more about Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical Flaw. Get up to date on the latest...
Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk
News

Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk

Telerik Report Server customers are being advised to update by Progress Software due to the identification of a critical security vulnerability that may allow remote code execution. The vulnerability affects Report Server versions 2024 Q2 (10.1.24.514) and earlier. It is listed as CVE-2024-6327 (CVSS score: 9.9). An insecure deserialization vulnerability in Progress Telerik Report Server versions older than 2024 Q2 (10.1.24.709) could allow for a remote code execution attack, the company warned in an advisory. Deserialization vulnerabilities arise when an application, in the absence of sufficient validation, reconstructs untrusted data under the control of an attacker, permitting the execution of unauthorized commands read more about Critical Flaw in Telerik Report Server Poses R...