CVE-2021-26360
published 2022-11-09CVE-2021-26360: An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.6th percentile
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_radeon_rx_6000_series_pro_w6000_series | >= AMD Radeon Pro Software Enterprise < 22.Q2 | 22.Q2 |
| amd | amd_radeon_rx_6000_series_pro_w6000_series | >= AMD Radeon Software < 22.5.2 | 22.5.2 |
| amd | amd_radeon_rx_6000_series_pro_w6000_series | >= Enterprise Driver < 22.10.20 | 22.10.20 |
| amd | enterprise_driver | < 22.10.20 | 22.10.20 |
| amd | radeon_pro_software | < 22.q2 | 22.q2 |
| amd | radeon_software | < 22.5.2 | 22.5.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hw: amd: Unauthorized modifications of the security configuration of the SOC registers
vendor_redhat·2022-11-08·CVSS 7.8
CVE-2021-26360 [HIGH] hw: amd: Unauthorized modifications of the security configuration of the SOC registers
hw: amd: Unauthorized modifications of the security configuration of the SOC registers
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP.
A flaw was found in hw. This flaw allows an attacker with local access to the system to make unauthorized modifications to the security configuration of the SOC registers. This issue could allow potential corruption of the AMD secure processor’s encrypted memory contents, leading to arbitrary code execution in ASP.
Mitigation: Please contact AMD for more updates on this flaw.
Package: kernel (Red Hat Enterprise Linux 6) - Not affect
GHSA
GHSA-5v6h-fqxx-8wv5: An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers
ghsa_unreviewed·2023-07-06
CVE-2021-26360 [HIGH] CWE-284 GHSA-5v6h-fqxx-8wv5: An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP.
No detection rules found.
Exploit-DB
Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read
exploitdb·2024-03-11·CVSS 8.6
CVE-2023-26360 [HIGH] Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read
Adobe ColdFusion versions 2018_15 (and earlier) and 2021_5 and earlier - Arbitrary File Read
---
# Exploit Title: File Read Arbitrary Exploit for CVE-2023-26360
# Google Dork: [not]
# Date: [12/28/2023]
# Exploit Author: [Youssef Muhammad]
# Vendor Homepage: [
https://helpx.adobe.com/coldfusion/kb/coldfusion-downloads.html]
# Software Link: [
https://drive.google.com/drive/folders/17ryBnFhswxiE1sHrNByxMVPKfUnwqmp0]
# Version: [Adobe ColdFusion versions 2018,15 (and earlier) and 2021,5 and
earlier]
# Tested on: [Windows, Linux]
# CVE : [CVE-2023-26360]
import sys
import requests
import json
BANNER = """
██████ ██ ██ ███████ ██████ ██████ ██████ ██████ ██████ ██████ ██████ ██████ ██████
██ ██ ██ ██ ██ ██ ████ ██ ██ ██ ██ ██ ██ ██ ████
██ ██ ██ █████ █████ █████ ██ ██ ██ █████ █████ █████
Nuclei
Adobe ColdFusion - Local File Read
nuclei·CVSS 9.8
CVE-2023-26360 [HIGH] Adobe ColdFusion - Local File Read
Adobe ColdFusion - Local File Read
Unauthenticated Arbitrary File Read vulnerability due to deserialization of untrusted data in Adobe ColdFusion. The vulnerability affects ColdFusion 2021 Update 5 and earlier as well as ColdFusion 2018 Update 15 and earlier
Template:
id: CVE-2023-26360
info:
name: Adobe ColdFusion - Local File Read
author: DhiyaneshDK,7own
severity: high
description: |
Unauthenticated Arbitrary File Read vulnerability due to deserialization of untrusted data in Adobe ColdFusion. The vulnerability affects ColdFusion 2021 Update 5 and earlier as well as ColdFusion 2018 Update 15 and earlier
impact: |
This vulnerability can lead to unauthorized access to sensitive information stored on the server.
remediation: |
Apply the necessary security patches or updates provided by
Bleepingcomputer
Hackers breach US govt agencies using Adobe ColdFusion exploit
blogs_bleepingcomputer·2023-12-05·CVSS 8.6
CVE-2023-26360 [HIGH] Hackers breach US govt agencies using Adobe ColdFusion exploit
## Hackers breach US govt agencies using Adobe ColdFusion exploit
## Bill Toulas
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning about hackers actively exploiting a critical vulnerability in Adobe ColdFusion identified as CVE-2023-26360 to gain initial access to government servers.
The security issue allows executing arbitrary code on servers running Adobe ColdFusion 2018 Update 15 and older, and 2021 Update 5 and earlier. It was exploited as a zero day before Adobe fixed it in mid-March by releasing ColdFusion 2018 Update 16 and 2021 Update 6.
At the time, CISA published a notice about threat actors exploiting the flaw and urged federal organizations and state services to apply the available security updates.
In an alert today, America's Cyber Defense Agen
HackerOne
Unauthenticated File Read Adobe ColdFusion
hackerone·2023-12-21·CVSS 8.6
[HIGH] Unauthenticated File Read Adobe ColdFusion
Unauthenticated File Read Adobe ColdFusion
Unauthenticated Arbitrary File Read vulnerability due to de serialization of untrusted data in Adobe ColdFusion.
## Impact
The impact of this vulnerability could result in unauthorized access to sensitive data and actions within the affected Adobe ColdFusion instances.
## System Host(s)
█████████
## Affected Product(s) and Version(s)
The vulnerability affects ColdFusion 2021 Update 5 and earlier as well as ColdFusion 2018 Update 15 and earlier
## CVE Numbers
CVE-2023-26360
## Steps to Reproduce
POST /cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/iedit.cfc?method=wizardHash&_cfclient=true&returnFormat=wddx&inPassword=foo HTTP/1.1
Host: ███
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/8
2022-11-09
Published