
Welcome to TheCyberThrone most exploited vulnerabilities review. This review is for the weeks ending Saturday, November 16, 2024.
FortiNet FortiManager
The vulnerability tracked as CVE-2024-23113, with a CVSS score of 9.8 and part of the CISA KEV catalog, A use of externally-controlled format string in Fortinet FortiOS versions allows attacker to execute unauthorized code or commands via specially crafted packets. This issue arises due to the use of externally-controlled format strings, enabling attackers to execute unauthorized code or commands via specially crafted packets. Successful exploitation of this vulnerability could lead to serious security implications for organizations using these Fortinet products. Users are advised to update their systems as soon as possible to mitigate this risk Nearly 998K devices are vulnerable to the flaw still
Microsoft Sharepoint
The vulnerability tracked as CVE-2024-38094 with a CVSS score of 7.2 and part of CISA KEV catalog,is a remote code execution vulnerability affecting Microsoft SharePoint. Microsoft recently disclosed that the vulnerability is being exploited to gain initial access to corporate networks by attackers. Researchers also observed that attackers are targeting vulnerable SharePoint servers using publicly disclosed SharePoint proof-of-concept exploit code to plant a web shell that they later leverage to gain privileges and pivot into the compromised network.
QNAP
The vulnerability tracked as CVE-2024-50387, detailed in a QNAP advisory was revealed at Pwn2Own 2024. It is a critical SQL injection (SQLi) vulnerability impacting QNAP’s SMB Service, which is the vendor’s implementation of the Server Message Block (SMB) protocol within QNAP NAS devices, enabling file sharing and network services across Windows and other operating systems.
LiteSpeed Cache WordPress Plugin
The vulnerability tracked as is CVE-2024-50550 with a CVSS score of 8.1, a privilege escalation vulnerability in LiteSpeed Cache plugin for WordPress, which is installed on over 6 million websites. An attacker could be leveraged to access backend databases as well to install arbitrary plugins or sniffers, leading attackers to exfiltrate payment card data and sensitive information of users
PTZ Cameras
The vulnerabilities tracked as CVE-2024-8956 and CVE-2024-8957 bot with a CVSS score 7.2 and part of CISA KEV catalog impact PTZ cameras, which are extensively used in organizations around the world for applications such as live streaming, security surveillance, and conference automation. These vulnerabilities can also be chained by attackers to execute arbitrary OS commands on these devices, as well as access sensitive data such as usernames, password hashes, and device configuration details.
This brings end of this week in review security coverage. Thanks for visiting TheCyberThrone. If you like us please follow us on Facebook, Twitter, Instagram


