vulnerability
CISA Malcolm
High
Summary
Several vulnerabilities in CISA Malcolm allow for denial-of-service attacks and arbitrary code execution. Versions prior to 26.06.1 and 26.07.1 are affected. The vulnerabilities stem from issues related to unbounded file extraction, improper authorization checks, and compressed data handling, leading to potential resource exhaustion and remote code execution. The CISA has released patches to address these issues.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data