Tag Archives: Software

Vulnerability CVE-2023-5363 in OpenSSL

[German]A vulnerability CVE-2023-5363 was found in the OpenSSL software. The initialization of the encryption key length and the initialization vector in OpenSLL is incorrect. However, a fix is already available for the Linux distributions Debian and Ubuntu.

Posted in Security, Software | Tagged , | Leave a comment

Cisco: New 0-day vulnerability (CVE-2023-20273) in IOS XE; already being exploited

[German]US vendor Cisco has publicly disclosed another 0-day vulnerability (CVE-2023-20273) in IOS XE as of October 20, 2023. This vulnerability is already being exploited in the wild to compromise systems. The vendor plans to provide fixes for the CVE-2023-20198 and … Continue reading

Posted in devices, Security, Software | Tagged , , | Leave a comment

VMMap v3.4 released

As of October 17, 2023 VMMap v3.4 has been released in Sysinternals Tools. VMMap is a utility for analyzing virtual and physical process memory on Windows.

Posted in Software | Tagged | Leave a comment

Over 32,000 Cisco components compromised via CVE-2023-20198 vulnerability

[German]Short note for users who have Cisco components with IOS XE in use and these components are accessible via the Internet. As of October 16, 2023, Cisco issued a security warning about the 0-day vulnerability CVE-2023-20198, which is unpatched so … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Warning: WinRAR vulnerability CVE-2023-38831 is exploited by Chinese and Russian hackers

[German]Warning to users of the WinRAR archive program. Various state threat actors from Russia and China are trying to exploit a vulnerability in the WinRAR archiving tool for Windows. Attackers can execute arbitrary code when unpacking archives via the CVE-2023-38831 … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Sonicwall: Security updates for SonicOS close nine vulnerabilities

In SonicOS there are several vulnerabilities (buffer overflows) that have received a CVSS index of up to 7.7. Sonicwall has therefore released software updates for SonicOS for their firewalls, that close new vulnerabilities (CVE-2023-39276, CVE-2023-39277, CVE-2023-39278, CVE-2023-39279, CVE-2023-39280, CVE-2023-41711 and … Continue reading

Posted in Security, Software, Update | Tagged , , | Leave a comment

Citrix NetScaler ADC and Gateway vulnerabilities (CVE-2023-4966 and CVE-2023-4967)

[German]There are serious vulnerabilities in older products from Citrix, as the manufacturer announced in a security alert. Both the Citrix NetScaler ADC and the Citrix NetScaler Gateway are affected by the vulnerabilities CVE-2023-4966 and CVE-2023-4967. An update is urgently recommended, … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

AI in medicine, questions and answers from Stanford

How will or can generative AI find its use in the medical field and what are the potentials as well as risks with this technology? In the USA, scientists are also dealing with this topic. Among them is the dean … Continue reading

Posted in General | Tagged , , | Leave a comment

Lancom (R&S) Firewalls (UF-xxx) no longer get signature updates from Oct. 1st till 4th 2023

[German]German blog reader Uwe Kernchen has just pointed out to me an issues that users and administrators of Lancom firewalls (also offered by Rhode & Schwarz) have hade. Since October 1, 2023, the UF-xxx firewalls no longer receive signature updates. … Continue reading

Posted in devices, Security, Software | Tagged , | Leave a comment

Warning about vulnerabilities in Exim Mail Transfer Agent (MTA)

[German]Another small addendum from the end of last week. There are several critical vulnerabilities in the Mail Transfer Agent (MTA) and open source mail server. CERT-Bund warns about these vulnerabilities, because attackers could execute arbitrary code via the SMTP service. … Continue reading

Posted in Security, Software | Tagged , | Leave a comment