HomeSecurityGladinet fixes active vulnerability in CentreStack

Gladinet patches active vulnerability in CentreStack

Gladinet , the company behind the CentreStack platform , has released a security update to fix a serious vulnerability exploited by malicious attackers. The flaw, known as unauthenticated local file inclusion , allows attackers to obtain the machine key and execute code remotely via a ViewState deserialization issue .

See also: Active vulnerability exploitation in Gladinet and TrioFox

Gladinet vulnerability

The vulnerability was first discovered by security researchers who observed unusual activity on systems running CentreStack. Unauthenticated local file inclusion is a type of flaw that allows an attacker to insert files from the server's local system without requiring authentication. This can lead to the disclosure of sensitive information, such as the machineKey, which is critical to the security of the application.

Gladinet responded promptly to the bug report and worked closely with the security community to develop and distribute an update that fixes the issue. This update is available to all CentreStack users and the company strongly recommends its immediate implementation to prevent potential attacks.

See also: Juniper Networks patches critical vulnerabilities in Junos Space

Gladinet patches active vulnerability in CentreStack

The flaw exploits a deserialization issue in ViewState, a technology used to maintain state in ASP.NET between HTTP requests. Deserialization is the process of converting data from a stored state format to a format that can be used by the program. When deserialization is not done in a secure manner, it could allow attackers to execute arbitrary code on the system.

Gladinet has also issued guidelines to strengthen the security of systems using CentreStack, suggesting measures such as using strong passwords, regularly updating software, and monitoring systems for unusual activity. The company emphasizes the importance of ongoing security education for users and system administrators to prevent future attacks.

This flaw highlights the importance of regularly updating systems and collaboration between software companies and the security community to address ever-evolving threats. Gladinet is committed to continuing to work on improving the security of its products and providing its customers with the best possible solutions to protect their data.

See also: GitHub Copilot: Vulnerability allows code extraction from private repositories

Gladinet patches active vulnerability in CentreStack

CentreStack users are encouraged to contact Gladinet customer support for more information on the update and recommended security practices. The company remains committed to providing secure and reliable solutions for its customers' needs.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS