On Monday researchers from Claroty released a report detailing two critical vulnerabilities in FileWave’s Mobile Device Management (MDM) system. These vulnerabilities consist of a hard-coded cryptographic key (CVE-2022-34906) and an authentication bypass (CVE-2022-34907), which have been patched in version 14.7.2 of the FileWave MDM. By leveraging these two exploits, the researchers were able to gain Super User access, access all data and credentials stored on the devices, achieve arbitrary remote code execution, and push malicious code — including ransomware — to all devices managed by the MDM.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security