Tag
Detection of Unauthorized Root or CA Certificate Installation
1 rule 1 TTPAdversaries can install malicious root or CA certificates into the Windows registry to facilitate traffic interception, bypass security controls, and establish persistence.
Authorization Bypass in Lemur Leading to Unauthorized Certificate Revocation
1 rule 5 TTPs 1 CVEAn authorization bypass vulnerability in Lemur allows authenticated users to revoke arbitrary certificates by creating duplicate certificate records and bypassing ownership and endpoint-attached safeguards.
CVE-2022-2068 c_rehash Command Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2022-2068 is a command injection vulnerability in the c_rehash script, requiring immediate attention to prevent potential arbitrary code execution.
Lego ACME Client Arbitrary File Write via Path Traversal
2 rules 1 TTPThe lego ACME client is vulnerable to arbitrary file write and deletion via path traversal, where a malicious ACME server can supply a crafted challenge token containing `../` sequences, causing lego to write attacker-influenced content to any path writable by the lego process, potentially leading to remote code execution, data destruction, or privilege escalation.