RCE Security
  • Home
  • About
  • Contact Us
  • Services
  • Research
Select Page

SAP Emarsys SDK for Android Sensitive Data Leak (CVE-2023-6542)

by Julien Ahrens | Thursday, April 10, 2025 | Advisory, CVE, Exploit

In late 2023, we’ve discovered and coordinated a quite interesting vulnerability affecting the Emarsys SDK for Android versions 3.6.1 and below with the respective vendor, SAP. While the overall coordination process went smoothly, the security advisory published...
SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897)

SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897)

by Julien Ahrens | Wednesday, April 12, 2023 | Advisory, CVE, Exploit

While my last finding affecting SecurePoint’s UTM was quite interesting already, I was hit by a really hard OpenSSL Heartbleed flashback with this one. The following exploit works against both the admin portal on port 11115 as well as the user portal on port...
SecurePwn Part 1: Bypassing SecurePoint UTM’s Authentication (CVE-2023-22620)

SecurePwn Part 1: Bypassing SecurePoint UTM’s Authentication (CVE-2023-22620)

by Julien Ahrens | Tuesday, April 11, 2023 | Advisory, CVE, Exploit

While working on a recent customer engagement, I discovered two fascinating and somewhat weird bugs in SecurePoint’s UTM firewall solution. The first one, aka CVE-2023-22620, is rated critical for an attacker to bypass the entire authentication and gain access...
From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225)

From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225)

by Julien Ahrens | Thursday, December 1, 2022 | Advisory, Bug Bounty, CVE

CVE-2020-16171: Exploiting Acronis Cyber Backup for Fun and Emails

CVE-2020-16171: Exploiting Acronis Cyber Backup for Fun and Emails

by Julien Ahrens | Monday, September 14, 2020 | Advisory, CVE

You have probably read one or more blog posts about SSRFs, many being escalated to RCE. While this might be the ultimate goal, this post is about an often overlooked impact of SSRFs: application logic impact. This post will tell you the story about an unauthenticated...

Dell KACE K1000 Remote Code Execution – the Story of Bug K1-18652

by Julien Ahrens | Tuesday, April 9, 2019 | Advisory, Bug Bounty

This is the story of an unauthenticated RCE affecting one of Dropbox’s in scope vendors during last year’s H1-3120 event. It’s one of my more recon-intensive, yet simple, vulnerabilities, and it (probably) helped me to become MVH by the end of the...
« Older Entries
  • X
  • RSS

Designed by Elegant Themes | Powered by WordPress