June 9, 2024
2 mins read

CERT-In finds multiple vulnerabilities in Android

The affected software includes Android versions 12, 12L, 13, and 14….reports Asian Lite News

The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics & Information Technology, on Friday warned users of multiple vulnerabilities in Android which could allow an attacker to obtain sensitive information, gain elevated privileges and cause denial-of-service (DoS) conditions on the targeted system.

The affected software includes Android versions 12, 12L, 13, and 14.

“Multiple vulnerabilities have been reported in Android which could be exploited by an attacker to obtain sensitive information, gain elevated privileges and cause a denial of service condition on the targeted system,” said the CERT-In advisory.

According to the cyber agency, these vulnerabilities exist in Android due to flaws in the Framework, System, Google Play system updates, Kernel, Arm components, MediaTek components, Imagination Technologies and Qualcomm closed-source components.

CERT-In advised users to apply appropriate updates when made available by the respective OEMs (original equipment manufacturers).

Last week, CERT-In warned about a vulnerability in Checkpoint Network Security gateway products, which could allow hackers to compromise users’ data.

According to its advisory by the national cyber-security agency, attackers can use the vulnerability to access certain information on “internet-connected gateways configured with IPSec VPN, remote access VPN, or mobile access software blades.”

Warning over bug in Checkpoint gateway products

CERT-In has warned about a vulnerability in Checkpoint Network Security gateway products, which could allow hackers to compromise users’ data.

According to its advisory by the national cyber-security agency, attackers can use the vulnerability to access certain information on “internet-connected gateways configured with IPSec VPN, remote access VPN, or mobile access software blades”.

This, in certain scenarios, could potentially lead the attacker to move laterally and gain domain admin privileges, warned the agency.

The vulnerability exists in Checkpoint Network Security gateway products due to the unrecommended password-only authentication method.

“The vulnerability (CVE-2024-24919) is being exploited in the wild,” said CERT-In, urging users to apply fixes issued by the company.

Checkpoint has discovered the vulnerability and issued the fix.

“Following our security update, Check Point’s dedicated task force continues investigating attempts to gain unauthorised access to VPN products used by our customers,” said the company in its security update.

“Exploiting this vulnerability can result in accessing sensitive information on the Security Gateway,” it added.

CERT-In, which comes under the Ministry of Electronics & Information Technology, last week warned users of vulnerabilities in Google Chrome and Siemens products, which could allow an attacker to execute arbitrary code on the targeted system.

ALSO READ: David Cameron falls victim to hoax video call

Previous Story

Modi to be sworn in as PM

Next Story

Pakistan, China agree to upgrade CPEC

Latest from India News

Recovery From Realty Stress Rises

Crisil expects residential demand in these markets to grow by 7–9 per cent in FY26, offering critical support to projects now being revived through restructuring Asset Reconstruction Companies (ARCs) are expected to

Kenya’s Odinga Slams Adani Deal U-Turn

Before the cancellation of the deal, Odinga was among the leaders who defended the Adani Group….reports Asian Lite News Kenya’s former Prime Minister Raila Odinga on Friday expressed disappointment over the cancellation

Stokes: Don’t Write India Off Yet

Stokes added that his side’s sole focus is limited to the India series and not thinking beyond. Ahead of the first Test of the five-match series, England captain Ben Stokes said that

Headingley Heat or Swing Trap

Jaffer pointed out that Joe Root is undoubtedly the main guy that India should be looking to dislodge, even as others, including skipper Ben Stokes, are in indifferent batting form…writes Niharika Raina

India Takes Yoga to the World

Ahead of June 21, yoga events are being held worldwide, promoting health, harmony, and well-being for the 11th IDY…reports Asian Lite News Marking a global celebration of India’s cultural heritage, the Indian
Go toTop

Don't Miss

WhatsApp working on passkey support for Android beta

The platform also rolled out a ‘link with phone number’

New Android malware discovered that steals passwords

On Google Play, both legitimate versions of these apps have