Qognify.Ocularis.EventCoordinator.Insecure.Deserialization

description-logoDescription

This indicates an attack attempt to exploit an Insecure Deserialization Vulnerability in Qognify Ocularis.
The vulnerability is due to insufficient validation of request to EventCoordinator endpoint. A remote unauthenticated attacker could exploit this vulnerability by sending a crafted serialized object to the target server. Successful exploitation can result in result in arbitrary code execution under the security context of the SYSTEM.

affected-products-logoAffected Products

Qognify Ocularis prior to Ocularis Base patch 6.0.0.195

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-08-03 18.132 Default_action:pass:drop
2021-07-22 18.125 Sig Added
2021-01-28 17.007