Database/Control plane, storage & DevOps

A10 Thunder ADC (CsrRequestView): An authenticated attacker can inject a system-call payload through the CsrRequestView
Impact
An authenticated attacker can inject a system-call payload through the CsrRequestView component (used for certificate-signing-request handling), running arbitrary code on the load balancer with the privileges of the vulnerable process.
Who can reach it
Requires authentication first — the advisory doesn't specify a high privilege tier, meaning even a lower-privileged operator account may be enough to trigger it.
What to do
Software upgrade to the fixed ACOS release per A10's advisory for CVE-2024-30368/CVE-2024-30369 (the two ship together). Upgrade and reboot each Thunder ADC instance; if it's fronting inference traffic, plan for a failover to a standby unit during the upgrade rather than a hard outage.
References
Related entries
- CyberPower PowerPanel MQTT message handling: An attacker with MQTT publish permissions can craft messagesCVE-2024-31856 · CyberPower PowerPanel MQTT message handlingHigh
- AMD Graphics Driver - crafted pointer leading to arbitrary code execution: Improper input validation in the AMDCVE-2024-36324 · AMD Graphics Driver - crafted pointer leading to arbitrary code executionHigh
- Jenkins: Agent processes can read arbitrary controller files via ClassLoaderProxy#fetchJarCVE-2024-43044 · JenkinsHigh
- Digi ConnectPort LTS (before 1.4.12): An attacker who can reach the ConnectPort LTS's file-upload featureCVE-2024-50627 · Digi ConnectPort LTS (before 1.4.12)High
- Deep Sea Electronics DSE855 generator communications gateway: Six unauthenticated flaws in one device: two stack-basedCVE-2024-5948 · Deep Sea Electronics DSE855 generator communications gatewayHigh
- PostgreSQL: TOCTOU race in pg_dumpCVE-2024-7348 · PostgreSQLHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.