CVE-2020-8688
published 2020-08-13CVE-2020-8688: Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.52%
72.0th percentile
Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | raid_web_console_3 | < 7.012.016.000 | 7.012.016.000 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Intel Raid Web Console 3 denial-of-service bugs
blogs_talos·2020-03-24·CVSS 8.8
[HIGH] Vulnerability Spotlight: Intel Raid Web Console 3 denial-of-service bugs
Geoff Serrao of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw.
Cisco Talos recently discovered two denial-of-service vulnerabilities in the web API functionality of Intel RAID Web Console 3. The Raid Web Console is a web-based application that provides several
configuration functions for the Intel RAID line of products, which includes controllers and storage expanders. The console monitors, maintains and troubleshoots these products. An attacker could exploit both of these bugs by sending a malicious POST request to the API.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Intel to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsIntel Raid Web Console 3 add server deni
Talos
Vulnerability Spotlight: Intel Raid Web Console 3 denial-of-service bugs
blogs_talos·2020-03-24·CVSS 8.8
[HIGH] Vulnerability Spotlight: Intel Raid Web Console 3 denial-of-service bugs
## Vulnerability Spotlight: Intel Raid Web Console 3 denial-of-service bugs
Geoff Serrao of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw.
Cisco Talos recently discovered two denial-of-service vulnerabilities in the web API functionality of Intel RAID Web Console 3. The Raid Web Console is a web-based application that provides several configuration functions for the Intel RAID line of products, which includes controllers and storage expanders. The console monitors, maintains and troubleshoots these products. An attacker could exploit both of these bugs by sending a malicious POST request to the API.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Intel to ensure that these issues are resolved and that an update is available for affected
Bugzilla
CVE-2019-8688 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8688 [HIGH] CVE-2019-8688 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8688 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0004 describes the following issue:
CVE-2019-8688
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0004.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
2020-08-13
Published