2023 Vulnerability Reports
CVE-2023-36424: VMware vCenter Server Authentication Bypass Technical deep-dive into the critical authentication bypass vulnerability affecting VMware vCenter Server 7.0 and 8.0, enabling unauthorized administrative access.
CVE-2023-27997: Fortinet FortiOS SSL-VPN Heap Buffer Overflow RCE (Volt Typhoon) Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2023-27997 affecting Fortinet FortiOS SSL-VPN Service.
CVE-2023-27532: Veeam Backup & Replication API Credential Disclosure In-depth technical breakdown of CVE-2023-27532: an unauthenticated credential disclosure vulnerability in the Veeam Backup Service API (TCP 9401), weaponized in ransomware intrusions and observed in the PaperCut adversary toolkit.
CVE-2023-21529: Microsoft Exchange Server RCE via Untrusted Deserialization Deep dive into the deserialization vulnerability in Microsoft Exchange Server exploited by Storm-1175 to deploy Medusa ransomware.
CVE-2023-20198: Cisco IOS XE Software Web UI Privilege Escalation Zero-Day Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2023-20198 affecting Cisco Systems Cisco IOS XE Web UI Subsystem.