Video: Top Cybersecurity Threats That You Need to Fix

Transcription

If you updated Chrome and SolarWinds Web Help Desk recently, get ready to update again – both have new flaws. And popular WordPress plugin and AWS's Application Load Balancer also have critical vulnerabilities. I’m Justin Fraction for eSecurity Planet. Let’s get into it. First Up: Critical WordPress Vulnerability Jeopardizes Millions of Sites Vulnerability Type: Privilege Escalation LiteSpeed Cache, a WordPress plugin designed to speed up caching and optimize page loads, has a vulnerability that puts over 5 million WordPress instances at risk.

A member of the PatchStack Alliance discovered this flaw, which was then reported to LiteSpeed Technologies. The issue lies in a user simulation feature that uses a weak security hash. This allows unauthenticated users to escalate their privileges and potentially upload malicious plugins or files. The fix: Upgrade to LiteSpeed version 6.4.1, which includes the necessary patch. Next Up: AWS Application Load Balancer Sees Configuration Issues Type of vulnerability: Configuration issue leading to authentication bypass.

The problem: A configuration vulnerability in Amazon Web Services' Application Load Balancer (ALB) authentication feature, discovered by Miggo, could allow a threat actor to bypass ALB security. If an application is misconfigured as an ALB target group and is directly accessible, attackers could exploit a shared public key server to set an arbitrary key ID. This vulnerability, dubbed ALBeast, stems from a lack of guidance on validating a token’s signer in AWS’s documentation, potentially leading applications to trust attacker-crafted tokens.

Applications exposed to the internet are especially vulnerable. AWS has since updated its documentation and added code to ensure authentication signatures are verified and validated. However, AWS does not consider this issue a formal vulnerability and is reaching out to customers with suboptimal configurations rather than altering the entire ALB component. The fix: Follow AWS's updated documentation and implement the new code for signature validation.

This ensures your applications are protected against potential exploits. At eSecurity Planet, we always recommend staying informed about vulnerabilities to protect your systems and networks. Check out our article on top Vulnerability Scanners and explore the links in the description! And back to the updates… Upgrade Chrome As Soon As Possible Type of vulnerability: Type confusion. The problem: A bug in the V8 JavaScript and Web Assembly engine impacts Google Chrome on PCs.

This vulnerability allows remote attackers to exploit heap correction using specifically crafted HTML pages, potentially taking control of your Chrome instance. Tracked as CVE-2024-7971, it affects versions of Chrome prior to 128.0.6613.84. The fix: Google’s stable channel updates include versions 128.0.6613.84/.85 for Windows and Mac, and 128.0.6613.84 for Linux. To update: Open Chrome and click the three vertical dots in the upper-right corner.

Select Help, then About Chrome. If an update is available, Chrome will automatically update. Click Relaunch to apply it. Another SolarWinds Web Help Desk Flaw Has Emerged Type of vulnerability: Hardcoded credential. The problem: Last week, on eSecurity Planet, writer Jenna Phipps mentioned a Java deserialization flaw in SolarWinds Web Help Desk. This week, researchers have discovered another vulnerability in WHD, this one a hardcoded credential issue.

If exploited, it allows an unauthenticated remote user to access the Web Help Desk’s controls and modify its data. Zach Hanley of Horizon3.ai discovered and reported the vulnerability. The flaw is tracked as CVE-2024-28987 and has a CVSS score of 9.1. The fix: SolarWinds has released a hotfix, 12.8.3 number 2, that solves both last week’s remote code execution vulnerability and this week’s credential one. CISA Adds Versa Director Vulnerability to Catalog Type of vulnerability: Dangerous file type upload vulnerability.

The problem: Versa Networks’ Director product has GUI customization options available for users who have Provider-Data-Center-Admin or Provider-Data-Center-System-Admin permissions. According to NIST, a malicious user with those privileges could use the “Change Favicon” option within the GUI to upload a malicious file that has a .png extension. The file would masquerade as an image file, according to NIST. The exploit is only possible after a user with the correct privileges has logged into the Versa Director GUI successfully.

Versa Networks noted that managed service providers are likely to be the main targets. The vulnerability is tracked as CVE-2024-39717 and has a severity rating of 6.6. The CISA has added this vulnerability to its catalog of Known Exploited Vulnerabilities (KEV). It has a High severity rating. According to NIST, Versa Networks is aware of one instance where the vulnerability was exploited because the customer didn’t implement older firewall guidelines.

The fix: To remediate CVE-2024-39717, upgrade to one of the following updated versions, with links to the download page provided by Versa Networks down in the description: 21.2.3: 22.1.2: 22.1.3: 22.1.4: Not affected. Additionally, follow all of Versa Networks’ firewall guidelines and hardening best practices. Double RCE Vulnerabilities Affect GPS Tracking Tool Traccar [Tracker] Type of vulnerability: Path traversal leading to potential remote code execution.

The problem: Open-source GPS tracking solution Traccar has two path traversal vulnerabilities that could allow unauthenticated threat actors to execute code remotely. According to Horizon3.ai, Traccar is vulnerable when guest registration is enabled, which is its default configuration. Traccar allows users to register their devices to be tracked, and Traccar shows their location when the devices communicate with the Traccar server. In version 5.1 of the solution, an image upload feature allows users to upload a picture of their device, but Traccar’s code has vulnerabilities in managing image file uploads.

The first vulnerability is tracked as CVE-2024-24809 and has a CVSS score of 8.5, with a high rating. The second is tracked as CVE-2024-31214 and has a critical CVSS score of 9.7. Both allow remote code execution if exploited. According to Horizon3.ai researcher, Naven Sunkavally, “The net result of CVE-2024-31214 and CVE-2024-24809 is that an attacker can place files with arbitrary content anywhere on the file system,” he said. “However, an attacker only has partial control over the filename.” The filename has to be a particular structure for the attackers to be successful.

The fix: Naveen recommends upgrading to Traccar 6. Alternatively, you can switch the registration setting to false, so user self-registration isn’t automatically enabled. That wraps up our list of security updates you should fix for late August 2024. Remember, staying informed about these vulnerabilities is crucial for protecting your systems and data. Be sure to apply the recommended fixes and updates as soon as possible. For more in-depth cybersecurity news and analysis, visit our website, at eSecurity Planet.

Don't forget to like, subscribe, and hit the notification bell to stay up-to-date with the latest security insights. Thanks for watching, and stay safe!

Stay informed about critical security issues. We cover a WordPress vulnerability, the need to update Chrome, and more. Protect your online presence — watch now.

Nov 6, 2024
1 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Discover the actions you can take to protect your online presence from cybersecurity threats in this video. We’ll explore the details of current vulnerabilities, their potential impact on your website, and the crucial steps you should implement to safeguard your data. We start with a critical WordPress vulnerability that threatens millions of sites, followed by configuration issues with AWS Application Load Balancer and the urgent need to upgrade Chrome. Additionally, we’ll discuss a new SolarWinds Web Help Desk flaw, CISA’s addition of the Versa Director vulnerability to its catalog, and double RCE vulnerabilities affecting the GPS tracking tool Traccar. Whether you’re a website owner, developer, or simply interested in security, this video is a must-watch. Be sure to subscribe for more updates and best practices to stay secure!

To read about these vulnerabilities, see our full vulnerability recap. Also check out the top network security threats, including defenses for each one, to make sure you stay protected.

Meghan Lafferty

Meghan Lafferty is the associate director of content for TechnologyAdvice's enterprise IT–focused websites. Meghan supports the writers and editors for the sites to provide the best, most comprehensive answers to readers' questions, and she also serves as the managing editor for eSecurity Planet. Prior to joining TechnologyAdvice, Meghan worked for Selling Signals, an online publication geared toward B2B sales professionals, and a healthcare trade publication, as well as multiple nonprofit organizations.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.