Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Carly Fortune is called the Queen of the Beach – and she’s done with haters

Editor’s Favorite Prime Day Kitchen Deals: Ninja, Keurig, and KitchenAid are on sale

Madonna and Charlie XCX sit together at YSL men’s fashion show in Paris

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » The flaws in the unpatched concerto will cause attackers to escape Docker and escape the host of compromise
Celebrities

The flaws in the unpatched concerto will cause attackers to escape Docker and escape the host of compromise

By May 22, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 22, 2025Ravi LakshmananVulnerabilities/Software Security

Cybersecurity researchers have revealed several critical security vulnerabilities affecting Versa Compato Network Security and SD-WAN orchestration platforms that can be exploited to control instances of sensitivity.

It should be noted that despite responsible disclosure on February 13, 2025, the identified drawbacks do not remain, despite prompting the issue to be published after the 90-day deadline.

“These vulnerabilities could allow attackers to compromise both their applications and the underlying host system when chained,” Project Decker researchers Harsh Jaiswal, Rahul Maini and Parth Malhotra said in a report shared with Hacker News.

Cybersecurity

The security flaws are listed below –

CVE-2025-34025 (CVSS score: 8.6) – Privilege escalation and docker container escape vulnerability that can be exploited to acquire code execution on the underlying host machine CVE-2025-34026, which is caused by an insecure default mount of host binary paths, and that can be exploited to acquire code execution on the underlying host machine CVE-2025-34026, allowing the management endpoint to be accessed. It may then be utilized to access heap dumps and trace logs by leveraging the internal spring boot actuator endpoint via CVE-2024-45410 CVE-2025-34027 (CVSS score: 10.0). It can be exploited to achieve remote code execution by exploiting endpoints related to uploading packages (“/portalapi/v1/package/spack/upload”) via any file.

The successful exploitation of CVE-2025-34027 allows attackers to take advantage of the race conditions to write malicious files to disk, and ultimately use LD_PRELOAD and a reverse shell to perform remote code execution.

“Our approach included overriding. ../../../../etc/ld.so.preload has a path pointing to /tmp/hook.so,” the researcher said. “At the same time, I uploaded /tmp/hook.so containing the C binary compiled for the reverse shell. The request triggered two file write operations, so I leveraged this so that both files were written within the same request.”

Cybersecurity

“If these files are written successfully, the command execution on the system will run /tmp/hook.so while both persistent command executions, which will result in a reverse shell.”

Without official fixes, users are advised to block semicolons in the URL path and block drop requests when the connection header contains the value x-real-ip. It is also recommended to monitor network traffic and logs for suspicious activity.

Hacker News has reached out to the Versa network for comments and will update the story if there is a reply.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleUniversity of Bristol Semiconductor Devices Unlock 6G Infrastructure
Next Article Hong Kong passes the Stubcoin bill as more governments recognize digital assets

Related Posts

How Jay-Z achieved his hair makeover

June 23, 2026

Amelia Gray Hamlin goes see-through in Saint Laurent

June 23, 2026

Zoey Deutch shows off her easy summer style on ‘The Tonight Show’

June 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Carly Fortune is called the Queen of the Beach – and she’s done with haters

Editor’s Favorite Prime Day Kitchen Deals: Ninja, Keurig, and KitchenAid are on sale

Madonna and Charlie XCX sit together at YSL men’s fashion show in Paris

Zendaya and Tom Holland confirm marriage, share sweet photo

Trending Posts

Madonna and Charlie XCX sit together at YSL men’s fashion show in Paris

June 23, 2026

Zendaya and Tom Holland confirm marriage, share sweet photo

June 23, 2026

How Jay-Z achieved his hair makeover

June 23, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.