Vulnerability Summary for the Week of March 17, 2025

High Vulnerabilities

Primary
Vendor — Product
Description Published CVSS Score Source Info
Synology–Unified Controller (DSMUC)
 
Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors. 2025-03-19 10 CVE-2024-10442
IBM–AIX
 
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls. 2025-03-18 10 CVE-2024-56346
Fortinet–FortiMail
 
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request. 2025-03-18 9.8 CVE-2023-47539
Synology–DiskStation Manager (DSM)
 
Improper encoding or escaping of output vulnerability in the system plugi

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from Bulletins

Read the original article: