2024 Vulnerability Reports
CVE-2024-57728 : SimpleHelp Arbitrary File Upload Analysis of a critical Zip Slip vulnerability in SimpleHelp remote support software v5.5.7 and earlier, allowing authenticated admin users to achieve remote code execution.
CVE-2024-5184: EmailGPT Direct Prompt Injection & Email Data Exfiltration Detailed vulnerability analysis of CVE-2024-5184 in EmailGPT: prompt injection in email assistant workflows leading to system instruction disclosure and private correspondence exfiltration.
CVE-2024-47575: Fortinet FortiManager fgfmd Authentication Bypass & Remote Code Execution (FortiJump) Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2024-47575 affecting Fortinet FortiManager Central Management Console.
CVE-2024-3400: Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2024-3400 affecting Palo Alto Networks PAN-OS GlobalProtect.
CVE-2024-21762: Fortinet FortiOS SSL-VPN Out-of-Bounds Write Remote Code Execution Zero-Day Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2024-21762 affecting Fortinet FortiOS SSL-VPN Gateway.
CVE-2024-20359: Cisco ASA and FTD Persistent Local Code Execution (Line Runner / ArcaneDoor) Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2024-20359 affecting Cisco Systems Cisco Adaptive Security Appliance (ASA) Core OS.
CVE-2024-20353: Cisco ASA and FTD Web Server Denial of Service & Memory Corruption (ArcaneDoor) Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2024-20353 affecting Cisco Systems Cisco Adaptive Security Appliance (ASA) & Firepower Threat Defense (FTD).
CVE-2024-0012: Palo Alto Networks PAN-OS Management Web Interface Authentication Bypass Comprehensive vulnerability intelligence, technical root cause analysis, and defensive engineering for CVE-2024-0012 affecting Palo Alto Networks PAN-OS Management Interface.