4.9 • 696 Ratings
🗓️ 17 January 2024
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, January 17th, 2024 edition of the Science and its Storm Center's Stormcast. |
0:09.6 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:15.5 | Quick update on Yvante, we do certainly see some initial scanning in our honeypots. Again, our honeypots are not |
0:23.5 | specifically emulating this vulnerability. So what we're seeing are internet-wide scans, |
0:29.7 | meaning that if you are running a vulnerable instance, assume compromise at this point. |
0:37.0 | Well, Lexity, the company had originally detected, |
0:40.3 | the exploitation of the vulnerability, |
0:42.3 | says that they are now aware |
0:45.5 | based on their own scanning of 1,700 exploited devices. |
0:51.9 | Not to be outdone by Yvanti, our other favorite security grabware vendor Citrix has published an advisory with details regarding two vulnerabilities. |
1:03.9 | The first one is a denial of service vulnerability CVE 2023-6549. |
1:09.9 | The second one is an off-occation remote code execution vulnerability on the management interface, CVE |
1:18.3 | 2023-6548. |
1:20.9 | That, again, is apparently already being exploited. |
1:25.3 | They also, again, recommend that the appliance's management interface should be |
1:29.8 | separated either physically or logically from normal network traffic. That should be really |
1:36.7 | understood for all of these type of devices, but apparently people aren't listening and there's |
1:43.1 | still thousands of them |
1:44.3 | connected directly to the internet. Patches have been made available by Citrix for all currently |
1:51.5 | supported versions of NetSkiller ADC and NetSkaler Gateway. Apparently, some older versions no longer |
1:59.3 | supported like the earlier versions of 12.1 are |
2:02.9 | vulnerable as well. One place where I have seen NetSkiller being deployed somewhat frequently |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.