
SANS Stormcast: Multiple Actively Exploited Vulnerabilities Including Checkpoint, Arista, and F5
This September 22nd, 2016 SANS Internet Storm Center Stormcast covers multiple actively exploited vulnerabilities. A checkpoint management server vulnerability allows arbitrary code execution through a file upload issue exploiting directory traversal, with a hotfix released. Arista's Cloud Orchestrator on-premise version has an actively exploited vulnerability with CVSS 3.1 score of 10 and version 4.0 score of 9.5 that affects confidentiality, integrity, and availability. F5 released patches for an actively exploited buffer overflow vulnerability in BIG-IP Access Policy Manager affecting devices configured as OAuth authorization servers. The episode also mentions a follow-up diary about HTTP GET requests with message bodies, noting that Apache accepts them while most other web servers ignore the body, and lighttpd returns an error. Nightmare Eclipse released another Windows Defender vulnerability that fills up disk space preventing update downloads.