[security bulletin] HPESBHF03710 rev.1 - HPE Intelligent Management Center (IMC) PLAT, Multiple Remote Vulnerabilities

2017-03-07 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03710en_us SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: hpesbhf03710en_us Version: 1

Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution

2017-03-07 Thread Securify B.V.
Stack-based buffer overflow in Western Digital My Cloud allows for remote code execution Remco Vermeulen, January 2017

SEC Consult SA-20170307-0 :: Unauthenticated OS command injection & arbitrary file upload in Western Digital WD My Cloud

2017-03-07 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20170307-0 > === title: Unauthenticated OS command injection & arbitrary file upload product: Western Digital My Cloud vulnerable version