News

Local Data Center Spurs Economic Growth, Part of the Cloud Located in Murfreesboro

BY BYRON GLENN Whenever someone tells you to “back your data up to the cloud,” have you ever asked yourself, “where exactly is the cloud?” Now, part of that cloud is right here in Murfreesboro. The question has scrambled our brains for years: What came first, the chicken or the egg? Although the world is still…

MS-ISAC CYBERSECURITY ADVISORY

TLP: WHITEMS-ISAC CYBERSECURITY ADVISORY DATE(S) ISSUED:06/09/2021 SUBJECT:Multiple Vulnerabilities in SAP Products Could Allow for Remote Code Execution OVERVIEW:Multiple vulnerabilities have been discovered in SAP products, the most severe of which could allow for remote code execution. SAP is a software company which creates software to manage business operations and customer relations. Successful exploitation of the…

Multiple Vulnerabilities in Adobe Products

MS-ISAC ADVISORY NUMBER: 2021-025 DATE(S) ISSUED: 02/10/2021 SUBJECT: Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution OVERVIEW: Multiple vulnerabilities have been discovered in Adobe Products, the most severe of which could allow for arbitrary code execution. Photoshop is Adobe’s flagship image editing software. Acrobat is a family of application software and Web…

Critical Patches Issued for Microsoft Products

MS-ISAC ADVISORY NUMBER: 2021-024 DATE(S) ISSUED: 02/09/2021 SUBJECT: Critical Patches Issued for Microsoft Products, February 09, 2021 OVERVIEW: Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges…

Vulnerabilities in SolarWinds Orion and ServU-FTP

DATE(S) ISSUED: 02/04/2021 SUBJECT: Multiple Vulnerabilities in SolarWinds Orion and ServU-FTP Could Allow for Remote Code Execution OVERVIEW: Multiple vulnerabilities have been discovered in SolarWinds Orion and ServU-FTP, the most severe of which could allow for remote code execution. SolarWinds Orion provides centralized monitoring across an organization’s entire IT stack. ServU-FTP is a multi-protocol file…

Vulnerability in SonicWall SMA 100 Series

DATE(S) ISSUED: 02/04/2021 SUBJECT: A Vulnerability in SonicWall SMA 100 Series Could Allow for SQL Injection OVERVIEW: A vulnerability has been discovered in the SonicWall SMA 100 Series, which could allow for SQL injection. The SonicWall SMA 100 Series is a unified secure access gateway that enables organizations to provide access to any application, anytime,…

MS-ISAC CYBERSECURITY ADVISORY

MS-ISAC CYBERSECURITY ADVISORY DATE(S) ISSUED: 02/03/2021 SUBJECT: Multiple Vulnerabilities in Cisco VPN Routers Could Allow for Arbitrary Code Execution. OVERVIEW: Multiple vulnerabilities have been discovered in Cisco VPN Routers, the most severe of which could allow for arbitrary code execution as the root user of an affected device. These VPN routers are often used to…

Zero Day Vulnerability in SonicWall

DATE: February 02, 2021 SUBJECT: CISA Releases Information on Zero Day Vulnerability in SonicWall SMA 100 Series Version 10.x Products CISA is aware of a vulnerability in SonicWall Secure Mobile Access (SMA) 100 series products. SMA 100 series products provide an organization’s employees with remote access to internal resources.  SonicWall security and engineering teams have…

Vulnerabilities in Cisco Products

DATE(S) ISSUED: 1/21/2021 SUBJECT: Multiple Vulnerabilities in Cisco Products Could Lead to Arbitrary Code Execution OVERVIEW: Multiple vulnerabilities have been discovered in Cisco’s SD-WAN, DNA Center, and Smart Software Manager Satellite products, the most severe of which could allow for arbitrary code execution with system privileges. SD-WAN is used for cloud-based network architecture DNA Center…

Oracle Quarterly Critical Patches

DATE(S) ISSUED: 01/19/2021 SUBJECT: Oracle Quarterly Critical Patches Issued January 19, 2021 OVERVIEW: Multiple vulnerabilities have been discovered in Oracle products, which could allow for remote code execution. SYSTEMS AFFECTED: Business Intelligence Enterprise Edition, versions 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0 Enterprise Manager Base Platform, versions 13.2.1.0, 13.3.0.0, 13.4.0.0 Enterprise Manager for Fusion Applications, version 13.3.0.0 Enterprise…

Vulnerabilities in Siemens Solid Edge Visualization

DATE(S) ISSUED: 1/14/2021 SUBJECT: Multiple Vulnerabilities in Siemens Solid Edge Visualization Could Lead to Arbitrary Code Execution (ICSA-21-012-04) OVERVIEW: Multiple vulnerabilities have been discovered in Siemens’ Solid Edge, the most severe of which could allow for arbitrary code execution in the context of the system process. Solid Edge is used for designing and viewing 2D…

Vulnerabilities in Siemens JT2Go and Teamcenter Visualization

DATE(S) ISSUED: 1/13/2021 SUBJECT: Multiple Vulnerabilities in Siemens JT2Go and Teamcenter Visualization Could Lead to Arbitrary Code Execution (ICSA-21-012-03) OVERVIEW: Multiple vulnerabilities have been discovered in Siemens’ JT2Go and Teamcenter Visualization products, the most severe of which could allow for arbitrary code execution in the context of the system process. JT2Go and Teamcenter Visualization are…