sec-consult.com
Actions
Media Outlet details
| Scope | N/A |
|---|---|
| Language | English |
| Country | Austria |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesLocal Privilege Escalation in Slate Digital Connect (macOS)
Management summary The Slate Digital Connect macOS application is vulnerable to Local Privilege Escalation due to insecure XPC Client validation. An attacker can abuse the Privileged Helper tool to get root access. The vendor was unresponsive and there is no patch available. Vendor description "Slate Digital was founded in 2008 with a mission to deliver exceptional audio production tools to musicians, engineers, producers, and content creators.
Navigating the ethical boundaries of independent security research: A comprehensive analysis of the consumer pet tracking ecosystem
Software Results Device A used a somewhat unconventional approach for session management. The API could be talked to with a fixed Authorization Token for both independent accounts – the only unique secret necessary is the “devicetoken”, which is static for the tracker device and has a lifetime that does not expire. We were able to query data over half a year later with the same parameters – no new session creation was necessary.
Broken Access Control in syracom AG Secure Login (2FA) for Atlassian Jira / Confluence / Bitbucket
Management summary The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket was vulnerable to a flaw that allowed attackers to bypass the implemented multi-factor authentication (MFA). Successful exploitation allowed an attacker with access to valid user credentials to completely bypass MFA protection. Vendor description "The ORIGINAL: Strong Security via 2FA auth.
Privilege Escalation via Binary Planting in Genetec-provided RabbitMQ in multiple Genetec products
Management summary The RabbitMQ installation on multiple Genetec products created a directory with weak permissions, which allowed any authenticated user to inject arbitrary code that was then executed by the service. A local attacker could exploit this vulnerability in combination with Rotten Potato or similar potato-family privilege escalation techniques to achieve SYSTEM-level privileges on the affected system.
Broken Access Control in Config Endpoint in LiteLLM
Management summary An incomplete authorization check in LiteLLM allowed low privileged attackers to access sensitive data on the host system. Vendor description “AI Gateway to provide model access, fallbacks and spend tracking across 100+ LLMs. All in the OpenAI format.” Source: https://www.litellm.ai/ Business recommendation The vendor provides a patch which should be installed immediately.
Broken Access Control in Open WebUI
Management summary An incomplete authorization check in Open WebUI allowed low privileged attackers to access sensitive Tool data. Vendor description "The self-hosted AI interface. Open WebUI is the platform for running AI on your own terms. Connect to any model—local or cloud. Extend with Python. Share what you build with 331K others. 270 million downloads and growing." Source: https://openwebui.com/ Business recommendation The vendor provides a patch which should be installed immediately.
Hands-Free Lockpicking: Critical Vulnerabilities in dormakaba’s Physical Access Control System
Unauthenticated Path Traversal (CVE-2025-59099) While reverse engineering the individual components of our dormakaba access manager, we identified that the web interface is served by the open-source webserver CompactWebServer. In this webserver, we quickly identified a path traversal vulnerability, which allows us to directly access most files on the filesystem via a simple GET request.
Local Privilege Escalation in Vienna Assistant (MacOS) - Vienna Symphonic Library
Management summary The Vienna Symphonic Library - Vienna Assistant software for MacOS utilizes a privileged helper to perform privileged actions. The NSXPC listener of the privileged helper, does not perform client validation at all leading to privilege escalation. Vendor description "We make products, tools and services that enable all creators and musicians to express their deepest emotions through technology, designed to augment their passion for music and musicality.
Multiple Privilege Escalation Vulnerabilities in Arturia Software Center MacOS
Management summary The Arturia Software Center was found to be vulnerable to local privilege escalation via multiple vectors. The privileged helper utilized by Arturia Software Center via XPC does not perform client validation. When installing a plugin a world writeable uninstall shell script will be installed, which is executed by root when uninstalling. The vendor was unresponsive and no patch is available.
Multiple Vulnerabilities in Quanos Content Solutions SCHEMA ST4
Management summary All on-premise versions of SCHEMA ST4 are affected by a local privilege escalation vulnerability that can also result in arbitrary file overwrite. The vulnerabilities originate from the Update Service’s .NET Remoting interface: one weakness stems from its insecure-by-design deserialization behavior when processing input from local callers, while the other arises from insufficient access control and authentication on the exposed named-pipe endpoint.