SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Apple Addressed High Severity Flaws in macOS, iOS – Patch Now
Apple April 2022 Security Update, two high severity zero-day flaws tracked as “CVE-2022-22674” and “CVE-2022-22675” have been reported in Apple macOS and iOS. Apple has released patches for these two zero-day CVEs affecting macOS and iOS. A critical vulnerability is, therefore, present in Apple macO...
CiscoKits TFTP Server Directory Traversal Vulnerability
CVE Research
CiscoKits TFTP Server Directory Traversal Vulnerability
SecPod Research Team member (Antu Sanadi) has found a Directory Traversal vulnerability in CiscoKits CCNA TFTP Server. The vulnerability is caused due to improper validation of ‘Read’ request containing ‘../’ sequences. The flaw can be exploited to read arbitrary files via directory traversal attack...

CVE Research
Automated Patching: A Sure Way to Deal with the Rising Rate of Vulnerabilities
According to a study by Ponemon Institute, 55% of enterprises say they spend more time manually navigating through the various processes involved in a patch management platform than actually patching vulnerabilities.

CVE Research
Understanding SanerNow Risk Prioritization Engine
With Advanced Vulnerability Management, SanerNow reveals a hundred thousand vulnerabilities in an account of devices. Risk Prioritization helps reduce the risk findings to a list of CVEs and CCEs that should be acted upon immediately for an organization. The aspects that assist Automated Decision Ma...

CVE Research
Cisco IOS XR Zero Day Vulnerability Being Actively Exploited in the Wild
A medium severity zero-day vulnerability has been found in the health check RPM of Cisco IOS XR – An Internetwork Operating System (IOS) that is shipped with Cisco’s networking equipment. This vulnerability (CVE-2022-20821) allows an unauthenticated, remote attacker to access the Redis instance runn...

CVE Research
Microsoft February 2022 Patch Tuesday Addresses 57 Vulnerabilities Including a Zero-Day.
Microsoft has released February Patch Tuesday security updates with a total of 57 detected Vulnerabilities, including zero-day and 0 critical rated vulnerabilities, using a vulnerability management tool. Hence the products covered in the Microsoft February 2022 patch Tuesday security update include ...

CVE Research
Why Is It Important To Prioritize Vulnerabilities Beyond CVSS?
We all know the importance of vulnerability management in cyber-security. The pace with which the vulnerabilities are rising and their patches overwhelmed enterprises to deal with every loophole. Hence, enterprises tend to focus on flaws with high severity from CVSS.


