The research and development activities conducted by Sync Security's Hacking Team in the "Offensive" area of Cyber Security, allowed the discovery of three security vulnerabilities unknown to the product vendor, these vulnerabilities are known as 0-DAY.
Starting from the first days of January 2021, Sync Security labs have been performing Advanced Penetration Testing activities on some open-source IT Management and HelpDesk assets. As a result of the meticulous analysis carried out, three 0-DAY vulnerabilities emerged and were immediately reported to the product vendor.
The reported anomalies presented different criticalities, from the exfiltration of sensitive data inside the database to the execution of actions normally not allowed. Following the report, a collaboration was established between the Sync Security Hacking Team and the Security and Dev group of the vendor. On the morning of March 4, 2021, the product patches were officially released to solve the above mentioned problems.
The Sync Security team has therefore responsibly handled the disclosure of the anomalies, requesting the publication of the CVEs only after the release of the patch by the vendor. To date, the vulnerabilities are recognized as CVE-2021-21255, CVE-2021-21324 and CVE-2021-21326, respectively.
The dedication, passion and experience of Sync Security's Hacking Team members, coupled with the stimulus, atmosphere and environment that the company prides itself on providing, has enabled the realization of this umpteenth milestone with the knowledge and desire to always reach new goals.