Tag: Vulnerability Disclosure Forensics

  • F5 Contributes to KEV Confusion

    F5 Contributes to KEV Confusion

    F5 is a technology vendor that sells a variety of networking technology including security products. With a considerable security portfolio and long tenure in the industry they are well positioned to observe known exploited vulnerabilities (KEV). Their staff frequently write blogs about threat actor activity, exploit campaigns, and associated topics. Unfortunately, while they have great…

  • Vulnerability Disclosure Forensics: /cgi-bin/upload.cgi

    Vulnerability Disclosure Forensics: /cgi-bin/upload.cgi

    Yesterday, Chris Sullo of Nikto fame, asked me a simple question; in so many words, what was the “first web vuln”. To be clear, he is asking about the first vulnerability in a web server / service / program. Seems relatively straight-forward but I challenge anyone to answer it with their own data set, especially…

  • The Curious Case of CVE-2015-2551 & CVE-2019-9081 – Doom and Gloom! Or not.

    The Curious Case of CVE-2015-2551 & CVE-2019-9081 – Doom and Gloom! Or not.

    What’s Your Story CVE-2015-2551? This CVE-2015-2551 entry seems straight-forward, based on the description provided by CVE or NVD. Looking at the change history on NVD it is a bit more informative: So the ID was created for the 2015 calendar year, apparently not used, rejected seven years later, and confirmed by the assigning CNA (Microsoft).…