Advisory ID: SYSS-2015-002Product: Kaspersky Endpoint Security for Windows (KES)Vendor: Kaspersky Lab ZAOAffected Version(s): 8.1.0.1042, 10.2.1.23Tested Version(s): 8.1.0.1042, 10.2.1.23Vulnerability Type: Use of a One-Way Hash without a Salt (CWE-759)Risk Level: LowSolution Status: FixedVendor Notification: 2015-02-19Solution Date: 2015-10-01Public Disclosure: 2015-10-01CVE Reference: Not yet assignedAuthors of Advisory: Sven Freund and Matthias Deeg (SySS GmbH)~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~Overview:Kaspersky Endpoint Security for Windows provides centralized protectionof Windows workstations and Windows servers from malware, potentiallydangerous programs and network attacks. It includes features such asdata encryption functionality for encrypting hard drives and removabledevices, centralized vulnerability flagging and virtual machine support(see [1]).~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Advisory ID: SYSS-2015-003Product: Kaspersky Small Office Security (KSOS)Vendor: Kaspersky Lab ZAOAffected Version(s): 13.0.4.233Tested Version(s): 13.0.4.233Vulnerability Type: Authentication Bypass Using an Alternate Path or Channel (CWE-288)Risk Level: MediumSolution Status: FixedVendor Notification: 2015-02-19Solution Date: 2015-10-01Public Disclosure: 2015-10-01CVE Reference: Not yet assignedAuthors of Advisory: Matthias Deeg and Sven Freund (SySS GmbH)~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~Overview:Kaspersky Small Office Security is an endpoint protection softwarewith many features like malware protection, defences against phishingattacks and exploits, data encryption and data backup functionality.The vendor Kaspersky describes the product as follows (see [1]):"Kaspersky Small Office Security delivers business-grade protectiontechnologies that are designed to be simple to install, configure andrun. The solution protects your Windows-based PCs & file servers andAndroid smartphones and tablets to safeguard your online bankingtransactions, your business data and the information your customersentrust to you."~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Advisory ID: SYSS-2015-001Product: Kaspersky Endpoint Security for Windows (KES)Manufacturer: Kaspersky Lab ZAOAffected Version(s): 8.1.0.1042, 10.2.1.23Tested Version(s): 8.1.0.1042, 10.2.1.23Vulnerability Type: Authentication Bypass Using an Alternate Path or Channel (CWE-288)Risk Level: MediumSolution Status: FixedVendor Notification: 2015-02-19Solution Date: 2015-10-01Public Disclosure: 2015-10-01CVE Reference: Not yet assignedAuthors of Advisory: Sven Freund and Matthias Deeg (SySS GmbH)~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~Overview:Kaspersky Endpoint Security for Windows provides centralized protectionof Windows workstations and Windows servers from malware, potentiallydangerous programs and network attacks. It includes features such asdata encryption functionality for encrypting hard drives and removabledevices, centralized vulnerability flagging and virtual machine support(see [1]).~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Note: the current version of the following document is available here:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04822825SUPPORT COMMUNICATION - SECURITY BULLETINDocument ID: c04822825Version: 1HPSBGN03424 rev.1 - HP Cloud Service Automation, Remote Authentication BypassNOTICE: The information in this Security Bulletin should be acted upon assoon as possible.Release Date: 2015-09-30Last Updated: 2015-09-30Potential Security Impact: Remote authentication bypassSource: Hewlett-Packard Company, HP Software Security Response Team
Note: the current version of the following document is available here:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04819635SUPPORT COMMUNICATION - SECURITY BULLETINDocument ID: c04819635Version: 1HPSBPV03516 rev.1 - HP VAN SDN Controller, Multiple VulnerabilitiesNOTICE: The information in this Security Bulletin should be acted upon assoon as possible.Release Date: 2015-09-29Last Updated: 2015-09-29Potential Security Impact: Disclosure of Privileged Information, RemoteDisclosure of Privileged InformationSource: Hewlett-Packard Company, HP Software Security Response TeamVULNERABILITY SUMMARYA potential security vulnerability has been identified with the HP VAN SDNController running SSLv3. This is the SSLv3 vulnerability known as "PaddingOracle on Downgraded Legacy Encryption" also known as "Poodle", which couldbe exploited remotely resulting in disclosure of privileged information.