From 246cdd6beafdafee68010470c8dd594e2484ef11 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 21 Feb 2025 03:32:45 +0000 Subject: [PATCH] Publish Advisories GHSA-gj4j-xh74-gvw8 GHSA-pv72-r6j5-c86m --- .../GHSA-gj4j-xh74-gvw8.json | 34 ++++++++++++++ .../GHSA-pv72-r6j5-c86m.json | 44 +++++++++++++++++++ 2 files changed, 78 insertions(+) create mode 100644 advisories/unreviewed/2025/02/GHSA-gj4j-xh74-gvw8/GHSA-gj4j-xh74-gvw8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pv72-r6j5-c86m/GHSA-pv72-r6j5-c86m.json diff --git a/advisories/unreviewed/2025/02/GHSA-gj4j-xh74-gvw8/GHSA-gj4j-xh74-gvw8.json b/advisories/unreviewed/2025/02/GHSA-gj4j-xh74-gvw8/GHSA-gj4j-xh74-gvw8.json new file mode 100644 index 00000000000..25c7ec1f532 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gj4j-xh74-gvw8/GHSA-gj4j-xh74-gvw8.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj4j-xh74-gvw8", + "modified": "2025-02-21T03:31:12Z", + "published": "2025-02-21T03:31:12Z", + "aliases": [ + "CVE-2024-38657" + ], + "details": "External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38657" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T02:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pv72-r6j5-c86m/GHSA-pv72-r6j5-c86m.json b/advisories/unreviewed/2025/02/GHSA-pv72-r6j5-c86m/GHSA-pv72-r6j5-c86m.json new file mode 100644 index 00000000000..1453bfc80a3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pv72-r6j5-c86m/GHSA-pv72-r6j5-c86m.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv72-r6j5-c86m", + "modified": "2025-02-21T03:31:12Z", + "published": "2025-02-21T03:31:12Z", + "aliases": [ + "CVE-2025-1001" + ], + "details": "Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An attacker could modify the server's response and deliver a malicious update to the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1001" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-051-01" + }, + { + "type": "WEB", + "url": "https://www.radiantviewer.com/files/RadiAnt-2025.1-Setup.exe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-21T01:15:09Z" + } +} \ No newline at end of file