Blog

Blog

LenovoEMC StorageCenter PX4-300R Unauthorized Remote File Retrieval

DDIVRT-2013-55 LenovoEMC StorageCenter PX4-300R Unauthorized Remote File RetrievalDate Discovered: October 10, 2013Discovery Credit: Evan Sylvester and r@b13$Vulnerability Description: The web server for the LenovoEMC StorageCenter PX4-300R allows unauthenticated remote users to retrieve specific files that are located outside of the web root. Malicious users would need to have direct knowledge of...
Blog

The Backdoor on the Side of Your Server

A note to our readers....The following is a blog post our organization was withholding while privately warning companies about a set of critical IPMI vulnerabilities in their rack mount hardware and the threat they posed to their security posture. Some of the content was covered in a B-Sides San Antonio talk two months ago by one of our researchers.Today the full-scope of this threat was...
Vulnerability Research

DDIVRT-2013-53 Actuate 'ActuateJavaComponent' Multiple Vulnerabilities

Follow us on Twitter! Severity--------High Date Discovered---------------March 19, 2013 Discovered By-------------Digital Defense, Inc. Vulnerability Research TeamCredit: Dennis Lavrinenko, Bobby Lockett, and r@b13$ 1. Actuate 'ActuateJavaComponent' Arbitrary File Retrieval Vulnerability Description-------------------------Actuate 10 contains a vulnerability within the 'ActuateJavaComponent'. This...
Vulnerability Research

DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory Traversal

DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory TraversalFollow us on Twitter! Title-----DDIVRT-2013-50 EverFocus EPARA264-16X1 Directory Traversal Severity--------High Date Discovered---------------January 22, 2013 Discovered By-------------Digital Defense, Inc. Vulnerability Research TeamCredit: r@b13$ Vulnerability Description-------------------------The EverFocus EPARA264-16X1 DVR allows...
Blog

Ensure Availability at a Reasonable Cost to Meet Business SLAs

Availability is a key indicator of how successfully an IT organization is supporting the company’s business objectives. Are required service levels in terms of workload volume and response times being achieved consistently for the business units? If not, the impact can be significant: a stoppage or slowdown can, in a matter of minutes, disrupt your supply chain and result in lost transactions,...
Blog

VMware View Connection Server Directory Traversal

DDIVRT-2012-48 VMware View Connection Server Directory Traversal (CVE-2012-5978)Follow us on Twitter!Severity--------HighDate Discovered---------------September 26, 2012Discovered By-------------Digital Defense, Inc. Vulnerability Research TeamCredit: r@b13$Vulnerability Description-------------------------The tunnel-server component of the VMware View Connection Server fails to ensure that each...