[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAK6eromgpY+LgvB1_YHKAubmoW9E7RNNvFAC471MoMGJiR_5-g@mail.gmail.com>
Date: Thu, 3 Oct 2019 22:26:12 -0400
From: Kevin Kotas via Fulldisclosure <fulldisclosure@...lists.org>
To: fulldisclosure@...lists.org
Subject: [FD] CA20190930-01: Security Notice for CA Network Flow Analysis
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
CA20190930-01: Security Notice for CA Network Flow Analysis
Issued: September 30th, 2019
CA Technologies, a Broadcom Company, is alerting customers to a
potential risk with CA Network Flow Analysis. A vulnerability exists
that can allow a remote attacker to execute arbitrary commands. CA
published a solution to address the vulnerabilities and recommends
that all affected customers implement this solution.
The vulnerability, CVE-2019-13658, occurs due to default credentials
and a configuration weakness. A malicious actor may use the default
credentials and exploit a weakness in the configuration to execute
arbitrary commands on the CA Network Flow Analysis server.
Risk Rating
High
Platform(s)
All supported platforms
Affected Products
CA Network Flow Analysis 10.0.x
CA Network Flow Analysis 9.x
How to determine if the installation is affected
Customers may use the product version to determine if their product
installation is affected.
Solution
The following solution is available to address the vulnerability.
Note that the typical deployment of CA Network Flow Analysis is in an
internal network and system administrators should restrict access to
sensitive ports (see Firewall Configuration) on the CA Network Flow
Analysis server.
CA Network Flow Analysis 9.x and 10.0.x:
Customers should update to CA Network Flow Analysis 10.0.2 or later
and change the MySQL passwords as described at Configure MySQL User
Password.
References
CVE-2019-13658 - CA Network Flow Analysis default credentials
Acknowledgement
CVE-2019-13658 - Hendrik Van Belleghem
Change History
Version 1.0: 2019-09-30 - Initial Release
CA customers may receive product alerts and advisories by subscribing
to Proactive Notifications on the support site.
Customers who require additional information about this notice may
contact CA Technologies Support at https://casupport.broadcom.com/
To report a suspected vulnerability in a CA Technologies product,
please send a summary to CA Technologies Product Vulnerability
Response at ca.psirt <AT> broadcom.com
Security Notices, PGP key, and disclosure policy and guidance
www.ca.com/us/support/ca-support-online/documents.aspx?id=177782
Kevin Kotas
CA Product Security Incident Response Team
Copyright 2019 Broadcom. All Rights Reserved. The term "Broadcom"
refers to Broadcom Inc. and/or its subsidiaries. Broadcom, the pulse
logo, Connecting everything, CA Technologies and the CA technologies
logo are among the trademarks of Broadcom. All trademarks, trade
names, service marks and logos referenced herein belong to their
respective companies.
-----BEGIN PGP SIGNATURE-----
Charset: utf-8
wsBVAwUBXZPob7Z6yOO9o8STAQhMrgf9HCSLc6uH4otJkEQIGNvVeNWaPDWTP9dm
ujWAXvnUJuL7lxzwEr31AAInxGHTi2dglMHoz7lBJ5KR7PCkTGImic1Oez+CyDt1
Pdu3KU/q4ZMRlek3BQZIwyDtCpa1v7jvd6YVAFACOKjK40abTaq5V7kKyRn33QWE
QG4wNiMj2Rh10v5wss00RxPHDO7OXFh8C1lXZMW7bFZ0XvpDml4jyOIsZ2vEodbA
JyFBJN970Ibea32wP0DhhDtW4A84q0V/6ZFlZboLoysuOHWJ65CNJH5waNkvjOyj
YsL1Vt+ou5O7VMY7mPjrh4IwJXdKSYZy+Vg9NcTAvDpzEnjH9ioGbA==
=zr/3
-----END PGP SIGNATURE-----
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists