

ICS: Schneider Electric EcoStruxure Products Vulnerability
January 29, 2025
Agent Tesla Malware – Active IOCs
January 30, 2025
ICS: Schneider Electric EcoStruxure Products Vulnerability
January 29, 2025
Agent Tesla Malware – Active IOCs
January 30, 2025Severity
High
Analysis Summary
CVE-2024-56626 CVSS:7.8
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write An offset from client could be a negative value, It could allows to write data outside the bounds of the allocated buffer.
CVE-2024-56627 CVSS:7.1
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read An offset from client could be a negative value, It could lead to an out-of-bounds read from the stream_buf.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2024-56626
CVE-2024-56627
Affected Vendors
Affected Products
- Linux Kernel Version 5.15 and more
Remediation
Refer to Linux Kernel Website for patch, upgrade, or suggested workaround information.