2015 m. spalio 3 d., šeštadienis

[SYSS-2015-002] Kaspersky Endpoint Security - Use of One-Way Hash withouth a Salt

Advisory ID: SYSS-2015-002
Product: Kaspersky Endpoint Security for Windows (KES)
Vendor: Kaspersky Lab ZAO
Affected Version(s): 8.1.0.1042, 10.2.1.23
Tested Version(s): 8.1.0.1042, 10.2.1.23
Vulnerability Type: Use of a One-Way Hash without a Salt (CWE-759)
Risk Level: Low
Solution Status: Fixed
Vendor Notification: 2015-02-19
Solution Date: 2015-10-01
Public Disclosure: 2015-10-01
CVE Reference: Not yet assigned
Authors of Advisory: Sven Freund and Matthias Deeg (SySS GmbH)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~

Overview:

Kaspersky Endpoint Security for Windows provides centralized protection
of Windows workstations and Windows servers from malware, potentially
dangerous programs and network attacks. It includes features such as
data encryption functionality for encrypting hard drives and removable
devices, centralized vulnerability flagging and virtual machine support
(see [1]).

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[SYSS-2015-003] Kaspersky Small Office Security - Authentication Bypass

Advisory ID: SYSS-2015-003
Product: Kaspersky Small Office Security (KSOS)
Vendor: Kaspersky Lab ZAO
Affected Version(s): 13.0.4.233
Tested Version(s): 13.0.4.233
Vulnerability Type: Authentication Bypass Using an Alternate Path or
                    Channel (CWE-288)
Risk Level: Medium
Solution Status: Fixed
Vendor Notification: 2015-02-19
Solution Date: 2015-10-01
Public Disclosure: 2015-10-01
CVE Reference: Not yet assigned
Authors of Advisory: Matthias Deeg and Sven Freund (SySS GmbH)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~

Overview:

Kaspersky Small Office Security is an endpoint protection software
with many features like malware protection, defences against phishing
attacks and exploits, data encryption and data backup functionality.

The vendor Kaspersky describes the product as follows (see [1]):

"Kaspersky Small Office Security delivers business-grade protection
technologies that are designed to be simple to install, configure and
run. The solution protects your Windows-based PCs & file servers and
Android smartphones and tablets to safeguard your online banking
transactions, your business data and the information your customers
entrust to you."

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[SYSS-2015-001] Kaspersky Endpoint Security - Authentication Bypass

Advisory ID: SYSS-2015-001
Product: Kaspersky Endpoint Security for Windows (KES)
Manufacturer: Kaspersky Lab ZAO
Affected Version(s): 8.1.0.1042, 10.2.1.23
Tested Version(s): 8.1.0.1042, 10.2.1.23
Vulnerability Type: Authentication Bypass Using an Alternate Path or
                    Channel (CWE-288)
Risk Level: Medium
Solution Status: Fixed
Vendor Notification: 2015-02-19
Solution Date: 2015-10-01
Public Disclosure: 2015-10-01
CVE Reference: Not yet assigned
Authors of Advisory: Sven Freund and Matthias Deeg (SySS GmbH)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~

Overview:

Kaspersky Endpoint Security for Windows provides centralized protection
of Windows workstations and Windows servers from malware, potentially
dangerous programs and network attacks. It includes features such as
data encryption functionality for encrypting hard drives and removable
devices, centralized vulnerability flagging and virtual machine support
(see [1]).

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[security bulletin] HPSBGN03424 rev.1 - HP Cloud Service Automation, Remote Authentication Bypass

Note: the current version of the following document is available here:
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c04822825

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c04822825
Version: 1

HPSBGN03424 rev.1 - HP Cloud Service Automation, Remote Authentication Bypass

NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible.

Release Date: 2015-09-30
Last Updated: 2015-09-30

Potential Security Impact: Remote authentication bypass

Source: Hewlett-Packard Company, HP Software Security Response Team

2015 m. spalio 2 d., penktadienis

[security bulletin] HPSBPV03516 rev.1 - HP VAN SDN Controller, Multiple Vulnerabilities

Note: the current version of the following document is available here:
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c04819635

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c04819635
Version: 1

HPSBPV03516 rev.1 - HP VAN SDN Controller, Multiple Vulnerabilities

NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible.

Release Date: 2015-09-29
Last Updated: 2015-09-29

Potential Security Impact: Disclosure of Privileged Information, Remote
Disclosure of Privileged Information

Source: Hewlett-Packard Company, HP Software Security Response Team

VULNERABILITY SUMMARY
A potential security vulnerability has been identified with the HP VAN SDN
Controller running SSLv3. This is the SSLv3 vulnerability known as "Padding
Oracle on Downgraded Legacy Encryption" also known as "Poodle", which could
be exploited remotely resulting in disclosure of privileged information.