{"id":41732,"date":"2024-01-23T15:48:40","date_gmt":"2024-01-23T14:48:40","guid":{"rendered":"https:\/\/www.wallix.com\/asistencia-y-servicios\/alertas-y-avisos\/"},"modified":"2026-07-17T16:12:42","modified_gmt":"2026-07-17T15:12:42","slug":"alertas-y-avisos","status":"publish","type":"page","link":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/","title":{"rendered":"Alertas y avisos"},"content":{"rendered":"\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-m193yzf3-415c4e5c5bb3aa0e06b9fd9d7e971da4\">\n#top .av-special-heading.av-m193yzf3-415c4e5c5bb3aa0e06b9fd9d7e971da4{\npadding-bottom:10px;\n}\nbody .av-special-heading.av-m193yzf3-415c4e5c5bb3aa0e06b9fd9d7e971da4 .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n.av-special-heading.av-m193yzf3-415c4e5c5bb3aa0e06b9fd9d7e971da4 .av-subheading{\nfont-size:15px;\n}\n<\/style>\n<div  class='av-special-heading av-m193yzf3-415c4e5c5bb3aa0e06b9fd9d7e971da4 av-special-heading-h1  avia-builder-el-0  el_before_av_section  avia-builder-el-no-sibling '><h1 class='av-special-heading-tag '  itemprop=\"headline\"  >Alertas de servicio<\/h1><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div>\n<\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-av_section-084070c6bfcb5f452bb0bcff0db88a95\">\n.avia-section.av-av_section-084070c6bfcb5f452bb0bcff0db88a95{\nbackground-color:#ffffff;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_1'  class='avia-section av-av_section-084070c6bfcb5f452bb0bcff0db88a95 main_color avia-section-default avia-no-border-styling  avia-builder-el-1  el_after_av_heading  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c\">\n#top .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-2  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >JULY 2026<\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>WSA-2026-07-0002 Unauthenticated Authentication Bypass in the SAML Service Provider &#8211; Access Manager<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div>\n<section  class='av_textblock_section av-av_textblock-564067357eb74c20cdd60b282c9b50bd '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><h1>2026-07-20- Unauthenticated Authentication Bypass in the SAML Service Provider &#8211; Access Manager<\/h1>\n<p><strong>Release Date:<\/strong>\u00a020 Jul 2026<\/p>\n<p><strong>Last Updated:<\/strong>\u00a020 Jul 2026<\/p>\n<p><strong>Identifiers:<\/strong>\u00a0WSA-2026-07-0002<\/p>\n<p><strong>Severity: <\/strong>HIGH- CVSS 4.0 Base 8.7 &#8211; CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:L\/UI:N\/VC:H\/VI:H\/VA:L\/SC:L\/SI:L\/SA:N<\/p>\n<h2>1. Executive Summary<\/h2>\n<p>\u26a0\ufe0f\u00a0<strong>This vulnerability affects any Access Manager with a SAML federation configured.<\/strong>\u00a0 Depending on the identity provider configuration, it may require no authentication and no user interaction.<\/p>\n<p>A high-severity vulnerability has been identified in the SAML Service Provider of the WALLIX Access Manager portal. A remote attacker with network access to the portal can obtain an authenticated administrator session without valid credentials.<\/p>\n<p>Because the Access Manager brokers access to a fleet of Bastions, an administrator session can reach the <strong>targets and privileged credentials the portal is configured to broker<\/strong> &#8211; i.e. the capabilities of a malicious Access Manager administrator. It does <strong>not<\/strong> grant administration of the Bastions themselves. We strongly urge affected customers to upgrade promptly and to review affected portals for signs of misuse. A security patch is available.<\/p>\n<p>? <strong>Coordinated public disclosure &#8211; act before September. <\/strong><\/p>\n<p>The independent security researchers who reported these vulnerabilities intend to publish full technical details in <strong>September 2026<\/strong> Once released, information useful to attackers will be in the public domain. Apply the fixes as soon as they are available and well ahead of the September disclosure.<\/p>\n<p><strong>Do not wait.<\/strong><\/p>\n<h2>2. Affected Products &amp; Scope<\/h2>\n<table>\n<tbody>\n<tr>\n<td><strong>Product<\/strong><\/td>\n<td><strong>Impacted Versions<\/strong><\/td>\n<td><strong>Status<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Access Manager<\/td>\n<td><strong>All versions with a SAML federation configured<\/strong><\/td>\n<td><strong>Vulnerable<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Access Manager<\/td>\n<td>Instances with\u00a0<strong>no SAML federation<\/strong>\u00a0configured<\/td>\n<td><strong>Not affected (via this vector)<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Access Manager<\/td>\n<td>5.1.10, 5.2.7, 6.0.4 and higher<\/td>\n<td><strong>Patched<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>? The defect is present in every reviewed version and no remediation commit exists as of\u00a05.1.9, 5.2.6 or 6.0.3.<\/p>\n<h3>? Risk Assessment<\/h3>\n<p>Exploitation requires network access to the portal&#8217;s SAML Assertion Consumer Service (ACS), exposed by default on 443. The attack surface is enabled as soon as at least one SAML federation domain exists on the portal \u2014 a common, documented enterprise deployment.<\/p>\n<p>Depending on your identity provider configuration, exploitation may require no authentication at all, or the ability to observe one legitimate SSO login. In either case the result is a privileged, unauthenticated authentication bypass.<\/p>\n<p>Hardened SAML settings do not mitigate this. Signature verification and IdP certificate pinning are performed and behave correctly; the vulnerability lies elsewhere in the validation flow.<\/p>\n<h2>3. Vulnerability Details<\/h2>\n<p><strong>Type:<\/strong>\u00a0CWE-347 (Improper Verification of Cryptographic Signature) ; CWE-290 (Authentication Bypass by Spoofing).<\/p>\n<p><strong>Description:<\/strong>\u00a0A flaw in the portal&#8217;s SAML response validation allows a remote attacker to have a forged SAML response accepted as valid and to be logged in under an attacker-chosen identity and privilege level, including the highest-privileged profile<\/p>\n<p>Technical exploitation details, indicators of compromise, and detection guidance are provided to customers in a dedicated, access-controlled Knowledge Base article ( WSA-2026-07-0002 &#8211; Unauthenticated Authentication Bypass in the SAML Service Provider &#8211; Access Manager), available through the support portal. They are intentionally withheld from this public advisory to protect customers until patch adoption is sufficiently widespread.<\/p>\n<h2>4. Detection<\/h2>\n<p>Unlike a silent credential bypass, this attack leaves traces in the portal application logs and in the front-end access logs. Log review is therefore meaningful.<\/p>\n<p>Precise indicators of compromise and log-review guidance are provided to customers in WSA-2026-07-0002 via the support portal.<\/p>\n<h2>5. Resolution &amp; Action Plan<\/h2>\n<h3>\u2705 Recommended Action: Apply the Security Patch<\/h3>\n<p>Upgrade to WALLIX Access Manager 5.1.10, 5.2.7, 6.0.4 or higher.\u00a0<strong>This is the only complete remediation.<\/strong><\/p>\n<p>The WALLIX ONE REMOTE ACCESS SaaS environments are already up to date.<\/p>\n<p>The WALLIX ONE PAM SaaS environments are currently being updated by WALLIX, in coordination with our customers<\/p>\n<p>After patching, and given that a session obtained through this flaw carries full administrative rights, we strongly recommend:<\/p>\n<ul>\n<li><strong>Audit accounts and configuration<\/strong>for unexpected administrators (federated or local) and unauthorized changes.<\/li>\n<li><strong>Rotate Access Manager administrator and API credentials.<\/strong><\/li>\n<li>Because the portal fronts the managed Bastions,\u00a0<strong>review privileged access and, where warranted, rotate secrets<\/strong>on Bastions reachable from a compromised portal.<\/li>\n<li>Remove any unrecognized JIT-provisioned federated users and invalidate their sessions.<\/li>\n<\/ul>\n<h3>\u26a0\ufe0f Interim Mitigations (until patching)<\/h3>\n<p>The SAML surface can be partially fenced:<\/p>\n<ul>\n<li><strong>Reduce exposure:<\/strong>disable or remove SAML federation domains that are not in active use; limit which organizations expose a SAML login.<\/li>\n<li><strong>Reduce exposure: <\/strong>Remove or rename profile of type Administrator on organizations which need SAML<\/li>\n<\/ul>\n<p>These reduce risk but do not fully close the flaw.\u00a0<strong>Upgrading remains the priority.<\/strong><\/p>\n<h2>Credits<\/h2>\n<p>This vulnerability was discovered and responsibly reported by <strong>Fabien J. (SNS-Security)<\/strong>. We thank SNS-Security for their coordinated disclosure.<\/p>\n<h2>Contact &amp; Support<\/h2>\n<p>For assistance with the mitigation steps, please contact our support by opening a ticket on the support portal.<\/p>\n<\/div><\/section>\n\n<p><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-av_section-8a088b55778457f770d97b418c17e050\">\n.avia-section.av-av_section-8a088b55778457f770d97b418c17e050{\nbackground-color:#e5e5e5;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_2'  class='avia-section av-av_section-8a088b55778457f770d97b418c17e050 main_color avia-section-default avia-no-border-styling  avia-builder-el-4  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c\">\n#top .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-av_heading-931ad82c3dd3fbacbce97a4dbf42eb7c av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-5  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >JULY 2026<\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>WSA-2026-07-0001 Unauthenticated Privilege Escalation in REST API &#8211; WALLIX Bastion<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div>\n<section  class='av_textblock_section av-av_textblock-564067357eb74c20cdd60b282c9b50bd '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><h1>2026-07-20 &#8211; Unauthenticated Privilege Escalation in REST API &#8211; Bastion<\/h1>\n<h1>[SECURITY ADVISORY] Unauthenticated Privilege Escalation in REST API &#8211; WALLIX Bastion<\/h1>\n<p><strong>Release Date:<\/strong> 20 Jul 2026<\/p>\n<p><strong>Last Updated:<\/strong> 20 Jul 2026<\/p>\n<p><strong>Identifiers:<\/strong> WSA-2026-07-0001<\/p>\n<p><strong>Severity:<\/strong> CRITICAL &#8211; CVSS 4.0 Base 10.0 &#8211; CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:H\/SI:H\/SA:H<\/p>\n<h2>1. Executive Summary<\/h2>\n<p>This vulnerability affects any operational Bastion 12.3 and 12.4.0 in any configuration.<\/p>\n<p>It requires no authentication, no user interaction, and no special settings.<\/p>\n<p>A critical vulnerability has been identified in the WALLIX Bastion REST API. A remote, unauthenticated attacker with network access to the API endpoint can obtain full administrative privileges on the appliance.<\/p>\n<p>Successful exploitation grants complete control over the Bastion, including its configuration, its vault of privileged credentials, and its session recordings. <strong>We strongly urge all affected customers to upgrade without delay<\/strong> and to treat affected appliances as potentially compromised. A security patch is available.<\/p>\n<p>? <strong>Coordinated public disclosure &#8211; act before September. <\/strong><\/p>\n<p>The independent security researchers who reported these vulnerabilities intend to publish full technical details in <strong>September 2026<\/strong> Once released, information useful to attackers will be in the public domain. Apply the fixes as soon as they are available and well ahead of the September disclosure.<\/p>\n<p><strong>Do not wait.<\/strong><\/p>\n<h2>2. Affected Products &amp; Scope<\/h2>\n<table>\n<tbody>\n<tr>\n<td><strong>Product<\/strong><\/td>\n<td><strong>Impacted Versions<\/strong><\/td>\n<td><strong>Status<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Bastion<\/td>\n<td>All versions <strong>12.0.x<\/strong><\/td>\n<td><strong>Not affected<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Bastion<\/td>\n<td>All versions\u00a0<strong>prior to 12.3.0<\/strong><\/td>\n<td><strong>Not affected<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Bastion<\/td>\n<td>All versions from<strong> 12.3.0 <\/strong>to<strong> 12.3.6 <\/strong><\/td>\n<td><strong>Vulnerable<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Bastion<\/td>\n<td>Version <strong>12.4.0<\/strong><\/td>\n<td><strong>Vulnerable<\/strong><\/td>\n<\/tr>\n<tr>\n<td>WALLIX Bastion<\/td>\n<td>Version <strong>12.3.7<\/strong><br \/>\nVersion <strong>12.4.1<\/strong> and higher<\/td>\n<td><strong>Patched<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The affected code path was introduced in the 12.3 branch. Versions below 12.3 are not affected.<\/p>\n<h3>? Risk Assessment<\/h3>\n<p>Exploitation requires only network access to the REST API endpoint (typically exposed on HTTPS \/ 443) on an operational appliance. No credentials, valid session, or user interaction are needed. Any Bastion actively in service should be considered exposed.<\/p>\n<h2>3. Vulnerability Details<\/h2>\n<p><strong>Type:<\/strong> CWE-290 (Authentication Bypass by Spoofing) \/ CWE-287 (Improper Authentication).<\/p>\n<p><strong>Description:<\/strong> Under certain conditions the REST API authentication layer can be induced to grant a privileged administrative session without valid credentials.<\/p>\n<p><strong>Access:<\/strong> Remote, network access to the API endpoint. <strong>No authentication required.<\/strong><\/p>\n<p>Technical exploitation details are intentionally withheld to protect customers until patch adoption is sufficiently widespread.<\/p>\n<h2>4. Detection &amp; Indicators of Compromise<\/h2>\n<p><strong>State-changing actions are logged.<\/strong> Operations that modify state (creating\/editing users, changing configuration) <strong>are<\/strong> recorded in \/var\/log\/wabaudit.log. Entries follow this format:<\/p>\n<p>wabengine: [wabaudit] action=\u00bb\u00bb type=\u00bb<object width=\"300\" height=\"150\">\u00bb object=\u00bb<name>\u00bb user=\u00bb<actor>\u00bb client_ip=\u00bb<ip>\u00bb infos=\u00bb<changed fields=\"\">\u00abThese informations are also sent to a SIEM system if configured.<strong>Primary indicator \u2014 administrator creation performed by the internal service account identity.<\/strong> A session obtained through this vulnerability acts as an internal service account principal from the loopback address. Any wabaudit.log entry such as the following is highly suspicious, because a legitimate administrator action is never recorded this way:Jul\u00a0 4 14:12:07 bastion wabengine: [wabaudit] action=\u00bbadd\u00bb type=\u00bbXXX\u00bb object=\u00bbXXX\u00bb user=\u00bbXXXX\u00bb client_ip=\u00bb127.0.0.1&#8243; infos=\u00bbcn [&#8216;backdoor&#8217;], profile [&#8216;product_administrator&#8217;], userPassword [&#8216;********&#8217;], userauths [&#8216;local_password&#8217; ]\u00bbLook in particular for:<\/p>\n<ul>\n<li>client_ip=\u00bb127.0.0.1&#8243;<strong>\u00a0on any state-changing action<\/strong>\u00a0(action=\u00bbadd\u00bb,\u00a0\u00abedit\u00bb,\u00a0\u00abdelete\u00bb) \u2014 especially\u00a0type=\u00bbUser\u00bb\u00a0creating a\u00a0product_administrator. This actor\/IP pair for administrative changes is the strongest indicator of exploitation.<\/li>\n<li>Creation of administrator accounts you did not provision, or configuration\/authorization changes with no matching interactive administrator login.<\/li>\n<\/ul>\n<p><strong>Review scope:<\/strong> examine \/var\/log\/wabaudit.log (and rotated archives) \u2014 and, for credential-checkout activity, \/var\/log\/vault-activity.log \u2014 across the entire window during which an affected version was network-reachable. Log review can confirm compromise but can never rule it out.<strong>Exploitation can be entirely invisible.<\/strong>Control Release of first version affected is 10 Feb 2026 , if you don\u00b4t have a logs retention (either on Bastion or in SIEM) before this date or installation of vulnerable version, you will not be able to assert if a exploitation was made.<strong>Absence of evidence must not be interpreted as absence of compromise<\/strong>. Treat any affected, network-reachable appliance as potentially fully compromised, including all vault secrets.<\/p>\n<h2>5. Resolution &amp; Action Plan<\/h2>\n<h3>Recommended Action: Apply the Security Patch<\/h3>\n<p>Upgrade to WALLIX Bastion <strong>12.4.1 <\/strong>or higher. <strong>This is the only effective remediation.<\/strong>The WOPAM SaaS environments are currently being updated by WALLIX, in coordination with our customers.Because exploitation may leave no trace (see \u00a74), after patching we strongly recommend, <strong>if you can not assert that no exploitation was made<\/strong>:<\/p>\n<ul>\n<li><strong>Rotate all secrets held in the vault<\/strong>(target account passwords, SSH keys, API keys). Assume every secret the appliance stored may have been read.<\/li>\n<li><strong>Rotate Bastion administrator and API credentials.<\/strong><\/li>\n<li><strong>Audit accounts and configuration<\/strong>for unexpected administrators or unauthorized changes, using the indicators in \u00a74.<\/li>\n<\/ul>\n<h2>Credits<\/h2>\n<p>This vulnerability was discovered and responsibly reported by <strong>Fabien J. (SNS-Security)<\/strong>. We thank SNS-Security for their coordinated disclosure.<\/p>\n<h2>Contact &amp; Support<\/h2>\n<p>For assistance with the mitigation steps, please contact our support by opening a ticket on the support portal.<\/p>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-lrz599mq-86b1025bf55bb7cc46bcc7daddc0142b\">\n.avia-section.av-lrz599mq-86b1025bf55bb7cc46bcc7daddc0142b{\nbackground-color:#e5e5e5;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_3'  class='avia-section av-lrz599mq-86b1025bf55bb7cc46bcc7daddc0142b main_color avia-section-default avia-no-border-styling  avia-builder-el-7  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f\">\n#top .av-special-heading.av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-lpmr3htm-ffc244d6815b8f4bea76ba8fe8dff77f av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-8  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >JULIO 2025<\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>CVE WSA-2025-07-001 Filtraci\u00f3n de credenciales de objetivos web<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><section  class='av_textblock_section av-lmrwphoe-9201705ebd7b14cf1bfb53a54de8c365 '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><p><strong>T\u00edtulo: CVE WSA-2025-07-001 Filtraci\u00f3n de credenciales de objetivos web<\/strong><strong> Fecha: Julio de 2025<\/strong><strong> Resumen<\/strong>Se <strong> ha descubierto una vulnerabilidad de gravedad alta (puntuaci\u00f3n base CVSS 7,7)<\/strong> en WALLIX Web Session Manager 4.0.7 (actualmente en versi\u00f3n controlada).<strong>Detalles de la vulnerabilidad<\/strong><strong>&#8211; Producto:<\/strong> Gestor de Sesiones Web WALLIX<strong>&#8211; Versi\u00f3n afectada:<\/strong> 4.0.7<strong>&#8211; Funcionalidad:<\/strong> Sesiones web con inyecci\u00f3n autom\u00e1tica de credenciales<strong>&#8211; Detalles de la vulnerabilidad:<\/strong> Cuando un usuario accede a una aplicaci\u00f3n web utilizando el flujo de trabajo de inyecci\u00f3n de credenciales, las credenciales de la aplicaci\u00f3n pueden quedar expuestas en el navegador y pueden recuperarse a trav\u00e9s de las herramientas de desarrollador del navegador.<strong>&#8211; Impacto:<\/strong> Las credenciales sensibles pueden filtrarse y utilizarse para acceder sin control a los objetivos- <strong>Gravedad:<\/strong>\u25e6 CVSS B\u00e1sico: <strong>7,7<\/strong> (\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N)\u25e6 CVSS Medioambiental: <strong>9,4<\/strong> (\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:N\/A:N\/E:H\/RL:O\/RC:C\/CR:H)<strong>Versiones de correcci\u00f3n<\/strong>La versi\u00f3n 4.0.9 de la correcci\u00f3n de WALLIX Web Session Manager estar\u00e1 disponible a principios de agosto de 2025.<strong>\u00bfC\u00f3mo comprobar si utilizo esa funci\u00f3n?<\/strong>1 Comprueba si has configurado un WALLIX Web Session Manager 4.0.7 =&gt; <em>Con\u00e9ctate como administrador a la soluci\u00f3n: el n\u00famero de versi\u00f3n se muestra en la p\u00e1gina de inicio.<\/em>2 Comprueba si has configurado objetivos de aplicaci\u00f3n web:1 Creaci\u00f3n de un objetivo de aplicaci\u00f3n web =&gt; <em>consulta<\/em> la <em>gu\u00eda de administraci\u00f3n funcional de WALLIX Bastion 12.2 \u00ab10.4.<\/em> A\u00f1adir una aplicaci\u00f3n web\u00bb secci\u00f3n <em>A\u00f1adir una aplicaci\u00f3n web\u00bb secci\u00f3n<\/em>2 Creaci\u00f3n de una cuenta de aplicaci\u00f3n web =&gt; <em> consulta la gu\u00eda de administraci\u00f3n funcional de WALLIX Bastion 12.2 \u00ab12.1<\/em> <em>A\u00f1adir cuentas de destino<\/em> <em> \u00ab<\/em> <em>secci\u00f3n<\/em>3 Cuenta de aplicaci\u00f3n web en un grupo de destino =&gt; <em> consulta la gu\u00eda de administraci\u00f3n funcional de WALLIX Bastion 12.2 \u00ab12.2 A\u00f1adir grupos de destino\u00bb secci\u00f3n<\/em>4 Pol\u00edtica de conexi\u00f3n web con credencial de inyecci\u00f3n como m\u00e9todo de autenticaci\u00f3n =&gt; <em>Consulta la gu\u00eda de administraci\u00f3n funcional de WALLIX Bastion 12.2 \u00ab11.3.1. Pol\u00edtica de conexi\u00f3n de aplicaciones web\u00bb. Secci\u00f3n \u00abPol\u00edtica de conexi\u00f3n de aplicaciones web<\/em><strong>Mitigaci\u00f3n<\/strong>WALLIX recomienda deshabilitar el flujo de trabajo de credenciales de inyecci\u00f3n con sesiones web y confiar en la autenticaci\u00f3n manual (inicio de sesi\u00f3n interactivo).<\/p>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-5m123x-a4736b45fe74d9a3265e59c3af4fd776\">\n.avia-section.av-5m123x-a4736b45fe74d9a3265e59c3af4fd776{\nbackground-color:#ffffff;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_4'  class='avia-section av-5m123x-a4736b45fe74d9a3265e59c3af4fd776 main_color avia-section-default avia-no-border-styling  avia-builder-el-10  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-3j2srh-439be97ed7a04d8a648afc18168ce86c\">\n#top .av-special-heading.av-3j2srh-439be97ed7a04d8a648afc18168ce86c{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-3j2srh-439be97ed7a04d8a648afc18168ce86c .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-3j2srh-439be97ed7a04d8a648afc18168ce86c .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-3j2srh-439be97ed7a04d8a648afc18168ce86c .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-3j2srh-439be97ed7a04d8a648afc18168ce86c .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-3j2srh-439be97ed7a04d8a648afc18168ce86c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-3j2srh-439be97ed7a04d8a648afc18168ce86c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-3j2srh-439be97ed7a04d8a648afc18168ce86c av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-11  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >MARZO 2025<\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>CVE XXX WSA-202503-1 AD Discovery: las credenciales de la cuenta de servicio configurada en la autenticaci\u00f3n externa se utilizan para recuperar datos de AD y los datos recuperados se env\u00edan en claro.<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><section  class='av_textblock_section av-2sf0al-810e05971651590eb81e3c11725c9a66 '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><div id=\"UniqueMessageBody\" class=\"XbIp4 jmmB7 GNqVo allowTextSelection OuGoX\" tabindex=\"-1\" role=\"document\" aria-label=\"Corps du message\">\n<div>\n<div>\n<div dir=\"ltr\">\n<div lang=\"fr\">\n<div>\n<div class=\"R1UVb\"><strong>CVE XXX WSA-202503-1 AD Discovery:<\/strong> las credenciales de la cuenta de servicio configurada en la autenticaci\u00f3n externa se utilizan para recuperar datos de AD y los datos recuperados se env\u00edan en claro.Se ha descubierto una vulnerabilidad alta (calificaci\u00f3n: CVSS 8.9).<strong>Productos afectados<\/strong><strong>&#8211; De la 10.0.0 a la 10.0.10, WALLIX Bastion inclu\u00eda<\/strong><strong>&#8211; De 12.0.0 a 12.0.8, WALLIX Bastion inclu\u00eda<\/strong><strong>&#8211; Todas las versiones fuera de soporte est\u00e1n potencialmente afectadas<\/strong><strong>Resumen<\/strong><strong>&#8211; Producto:<\/strong> WALLIX Bastion &#8211; M\u00f3dulo de descubrimiento<strong>&#8211; Funcionalidad:<\/strong> Descubrimiento de activos mediante una conexi\u00f3n cifrada autenticada por GSS-API\/STARTTLS a un Directorio Activo<strong>&#8211; Detalles de la vulnerabilidad:<\/strong> WALLIX Bastion env\u00eda informaci\u00f3n durante un escaneo, sobre dispositivos y sus cuentas con un Directorio Activo utilizando GSS-API o STARTTLS. Otras funciones que dependen de la integraci\u00f3n con Active Directory no se ven afectadas.<strong>&#8211; Impacto:<\/strong> Las credenciales de la cuenta de servicio pueden filtrarse y los datos confidenciales recuperados del Directorio Activo configurado no est\u00e1n cifrados.<strong>&#8211; Software fijo<\/strong><\/p>\n<p style=\"padding-left: 40px;\">&#8211; WALLIX Bastion 12.0.9 disponible 2025\/03\/26<\/p>\n<p style=\"padding-left: 40px;\">&#8211; Parche WALLIX Bastion 10 disponible 2025\/03\/28<\/p>\n<p>El siguiente Bolet\u00edn de Seguridad de WALLIX proporciona informaci\u00f3n sobre la vulnerabilidad, recomendaciones y soluciones: WSA-202503-1 https:\/\/support.wallix.com\/hc\/en-us\/articles\/25925255587613-WSA-202503-1<strong>CVE XXX WSA-202503-2 WIN RM<\/strong>Descubrimiento de AD: AD Discovery: las credenciales de la cuenta de servicio configurada durante un escaneo y utilizada para recuperar datos de AD y los datos recuperados se env\u00edan en claro.Se ha descubierto una vulnerabilidad alta (calificaci\u00f3n: CVSS 8.9).<strong>Productos afectados<\/strong>&#8211; De la 10.0.0 a la 10.0.10, WALLIX Bastion inclu\u00eda- De 12.0.0 a 12.0.8, WALLIX Bastion inclu\u00eda- Todas las versiones fuera de soporte est\u00e1n potencialmente afectadas<strong>Resumen<\/strong><strong>&#8211; Producto:<\/strong> WALLIX Bastion &#8211; M\u00f3dulo de descubrimiento<strong>&#8211; Funcionalidad:<\/strong> Descubrimiento de activos con el descubrimiento de cuentas activado<strong>&#8211; Detalles de la vulnerabilidad:<\/strong> WALLIX Bastion env\u00eda informaci\u00f3n durante una exploraci\u00f3n, sobre dispositivos y sus cuentas con un Directorio Activo. Otras funciones que dependen de la integraci\u00f3n con Active Directory no se ven afectadas.<strong>&#8211; Impacto:<\/strong> Las credenciales de la cuenta de servicio pueden filtrarse.<strong>&#8211; Software fijo<\/strong><\/p>\n<p style=\"padding-left: 40px;\">&#8211; WALLIX Bastion 12.0.9 disponible 2025\/03\/26<\/p>\n<p style=\"padding-left: 40px;\">&#8211; Parche WALLIX Bastion 10 disponible 2025\/03\/28<\/p>\n<p>El siguiente Bolet\u00edn de Seguridad de WALLIX proporciona informaci\u00f3n sobre la vulnerabilidad, recomendaciones y soluciones:WSA-202503-2 https:\/\/support.wallix.com\/hc\/en-us\/articles\/25925620269213-WSA-202503-2<strong>Funcionamiento y anuncios p\u00fablicos<\/strong>WALLIX no tiene conocimiento de ning\u00fan anuncio p\u00fablico o uso malintencionado de la vulnerabilidad descrita en este aviso. Sin embargo, se recomienda buscar cualquier actividad anormal en WALLIX Bastion y los Directorios Activos asociados.Para cualquier pregunta o informaci\u00f3n adicional, ponte en contacto con el equipo de asistencia en https:\/\/support.wallix.com.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-5g2aml-3d738db15a97eb851f16938c4b25f6d3\">\n.avia-section.av-5g2aml-3d738db15a97eb851f16938c4b25f6d3{\nbackground-color:#e5e5e5;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_5'  class='avia-section av-5g2aml-3d738db15a97eb851f16938c4b25f6d3 main_color avia-section-default avia-no-border-styling  avia-builder-el-13  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-485sh9-5579c89e5f117afc40ea5099bd8040fb\">\n#top .av-special-heading.av-485sh9-5579c89e5f117afc40ea5099bd8040fb{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-485sh9-5579c89e5f117afc40ea5099bd8040fb .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-485sh9-5579c89e5f117afc40ea5099bd8040fb .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-485sh9-5579c89e5f117afc40ea5099bd8040fb .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-485sh9-5579c89e5f117afc40ea5099bd8040fb .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-485sh9-5579c89e5f117afc40ea5099bd8040fb .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-485sh9-5579c89e5f117afc40ea5099bd8040fb .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-485sh9-5579c89e5f117afc40ea5099bd8040fb av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-14  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >NOVIEMBRE 2024<\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>CVE-2024-XXXXX &#8211; Evasi\u00f3n de cuenta de usuario desactivada \/ caducada<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><section  class='av_textblock_section av-2b280d-ac350d0b5bbc4d67702826a4109c2c73 '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><div id=\"UniqueMessageBody\" class=\"XbIp4 jmmB7 GNqVo allowTextSelection OuGoX\" tabindex=\"-1\" role=\"document\" aria-label=\"Corps du message\">\n<div>\n<div>\n<div dir=\"ltr\">\n<div lang=\"fr\">\n<div>\n<div class=\"R1UVb\">\n<div class=\"qF8_5\">\n<div data-olk-copy-source=\"MessageBody\">Se ha descubierto una vulnerabilidad CR\u00cdTICA (calificaci\u00f3n 9.1: CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:L\/A:L) en <b>WALLIX Bastion<\/b> y <b>WALLIX Access Manager<\/b>.Se ha solicitado un n\u00famero CVE, y actualmente estamos a la espera de su asignaci\u00f3n.<\/div>\n<h3><b>Resumen<\/b><\/h3>\n<div><\/div>\n<div><\/div>\n<div class=\"R1UVb\"><\/div>\n<div class=\"R1UVb\">\n<table id=\"x_x_table_0\" data-editing-info=\"{\" data-layout=\"default\" data-table-width=\"1606\" data-number-column=\"false\" data-testid=\"renderer-table\">\n<tbody>\n<tr>\n<td>\n<div><b>Producto<\/b><\/div>\n<\/td>\n<td>\n<div><b>Funci\u00f3n<\/b><\/div>\n<\/td>\n<td>\n<div><b>Detalles de la vulnerabilidad<\/b><\/div>\n<\/td>\n<td>\n<div><b>Impacto<\/b><\/div>\n<\/td>\n<td>\n<div><b>C\u00f3mo comprobar si utilizo esa funci\u00f3n<\/b><\/div>\n<\/td>\n<\/tr>\n<tr>\n<td data-colwidth=\"205\">\n<div>Basti\u00f3n WALLIX<\/div>\n<\/td>\n<td data-colwidth=\"289\">\n<div>Autenticaci\u00f3n de usuario con clave SSH almacenada en LDAP o Active Directory<\/div>\n<\/td>\n<td data-colwidth=\"341\">\n<div><b>El Basti\u00f3n WALLIX<\/b> no comprueba las banderas Caducado o Desactivado.<\/div>\n<\/td>\n<td data-colwidth=\"363\">\n<div>El usuario puede autenticarse en el Basti\u00f3n WALLIX y acceder a sus objetivos SSH<\/div>\n<\/td>\n<td data-colwidth=\"404\">\n<div>En <i>Configuraci\u00f3n &gt; Dominios de autenticaci\u00f3n &gt; Directorio Activo <\/i>o<i> LDAP, <\/i>se define el<i> atributo de clave p\u00fablica SSH <\/i><\/div>\n<\/td>\n<\/tr>\n<tr>\n<td data-colwidth=\"205\">\n<div>Basti\u00f3n WALLIX<\/div>\n<\/td>\n<td data-colwidth=\"289\">\n<div>Autenticaci\u00f3n de usuario con certificado X.509 almacenado en LDAP o Active Directory<\/div>\n<\/td>\n<td data-colwidth=\"341\">\n<div><b>El Basti\u00f3n WALLIX<\/b> no comprueba las banderas Caducado o Desactivado.<\/div>\n<\/td>\n<td data-colwidth=\"363\">\n<div>El usuario puede autenticarse en la GUI del Basti\u00f3n WALLIX y acceder a sus objetivos<\/div>\n<\/td>\n<td data-colwidth=\"404\">\n<div>Las dos condiciones siguientes se cumplen:<\/div>\n<ul data-indent-level=\"1\">\n<li>\n<div>En <i>Configuraci\u00f3n &gt; Opciones de configuraci\u00f3n<\/i> &gt; Configuraci\u00f3n X.509, <i>est\u00e1<\/i> marcada la opci\u00f3n <i>Activar autenticaci\u00f3n X.509<\/i>, y<\/div>\n<\/li>\n<li>\n<div>En <i>Configuraci\u00f3n &gt; Dominios de autenticaci\u00f3n &gt; Active Directory <\/i>o<i> LDAP<\/i>, <i>Activar autenticaci\u00f3n X509 <\/i>est\u00e1 marcado<\/div>\n<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td data-colwidth=\"205\">\n<div>Gestor de acceso WALLIX<\/div>\n<\/td>\n<td data-colwidth=\"289\">\n<div>Autenticaci\u00f3n de usuario con certificado X.509 almacenado en Active Directory<\/div>\n<\/td>\n<td data-colwidth=\"341\">\n<div><b>WALLIX Access Manager <\/b>no comprueba las banderas Caducadas.<\/div>\n<\/td>\n<td data-colwidth=\"363\">\n<div>El usuario puede autenticarse en la GUI de WALLIX Access Manager y acceder a sus objetivos<\/div>\n<\/td>\n<td data-colwidth=\"404\">\n<div>En la organizaci\u00f3n global, <i>Configuraci\u00f3n <\/i>&gt; <i>Dominios <\/i>&gt; Seleccionar dominio LDAP, <i>Permitir certificado X509 Autenticaci\u00f3n<\/i> se comprueba<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div>Nota: WALLIX Access Manager no admite la autenticaci\u00f3n de usuarios con certificado X.509 almacenado en LDAP.<\/div>\n<div>Nota: WALLIX Access Manager no permite la autenticaci\u00f3n de usuarios con clave SSH.<\/div>\n<div>Nota: Las credenciales de usuario (clave privada SSH o clave privada X.509 asociada al certificado) deben ser v\u00e1lidas.<\/div>\n<div>WALLIX recomienda aplicar inmediatamente las correcciones publicadas, o antes de aplicarlas, las soluciones alternativas descritas a continuaci\u00f3n.<\/div>\n<div><\/div>\n<div><\/div>\n<h3><b>Productos afectados<\/b><\/h3>\n<div><\/div>\n<\/div>\n<div><\/div>\n<div class=\"qF8_5\">\n<div><b>Basti\u00f3n:<\/b><\/div>\n<ul data-indent-level=\"1\">\n<li>\n<div>Incluye todas las versiones de WALLIX Bastion 12.0 hasta la 12.0.3<\/div>\n<\/li>\n<li>\n<div>Todos WALLIX Basti\u00f3n 11.0<\/div>\n<\/li>\n<li>\n<div>Todos los WALLIX Bastion 10.1, 10.2, 10.3, 10.4<\/div>\n<\/li>\n<li>\n<div>Todos los WALLIX Bastion 10.0 hasta 10.0.9 incluidos<\/div>\n<\/li>\n<li>\n<div>Todos los WALLIX Bastion 9.0, 9.1<\/div>\n<\/li>\n<li>\n<div>Todos los WALLIX Bastion anteriores pueden verse afectados<\/div>\n<\/li>\n<\/ul>\n<div><b>Gestor de acceso:<\/b><\/div>\n<ul data-indent-level=\"1\">\n<li>\n<div>Gestor de acceso WALLIX 5.1.0<\/div>\n<\/li>\n<li>\n<div>Todas las versiones de WALLIX Access Manager 5.0<\/div>\n<\/li>\n<li>\n<div>Todas las versiones de WALLIX Access Manager 4.4<\/div>\n<\/li>\n<li>\n<div>Incluye todas las versiones de WALLIX Access Manager 4.0 hasta la 4.0.7<\/div>\n<\/li>\n<li>\n<div>Todos los WALLIX Access Manager anteriores pueden verse afectados<\/div>\n<\/li>\n<\/ul>\n<h3><b>Indicador de compromiso<\/b><\/h3>\n<div><\/div>\n<div><\/div>\n<div>Comprueba el registro de autenticaci\u00f3n en WALLIX Bastion y WALLIX Access Manager para asegurarte de que no se han utilizado cuentas desactivadas o caducadas.<\/div>\n<div><\/div>\n<div><\/div>\n<h3><b>Soluciones<\/b><\/h3>\n<div><\/div>\n<div><\/div>\n<div><\/div>\n<div><b>Cuenta caducada y desactivada:<\/b><\/div>\n<div><\/div>\n<div>Para WALLIX Bastion y WALLIX Access Manager, elimina la clave SSH o el hash del certificado almacenado en la cuenta de usuario de Active Directory o LDAP.<\/div>\n<div>El certificado X.509 tambi\u00e9n puede ser revocado si las CRL est\u00e1n correctamente configuradas en WALLIX Bastion y WALLIX Access Manager<\/div>\n<div><\/div>\n<div><\/div>\n<div><\/div>\n<div><b>S\u00f3lo cuenta desactivada<\/b>:<\/div>\n<div><\/div>\n<div><\/div>\n<div>Si no puedes eliminar las claves SSH o el certificado X.509 dentro de Active Directory:<\/div>\n<ul data-indent-level=\"1\">\n<li>\n<div>WALLIX Bastion, ve a <i>Configuraci\u00f3n &gt; Opciones de configuraci\u00f3n<\/i> &gt; <i>Global<\/i> &gt; (Opciones avanzadas) &gt; <i>Atributos LDAP <\/i>y a\u00f1\u00e1delos:<\/div>\n<ul data-indent-level=\"2\">\n<li>\n<div>\u00abuserAccountControl\u00bb para Active Directory<\/div>\n<\/li>\n<li>\n<div>\u00abkrbPasswordExpiration\u00bb para FreeIPA.<\/div>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<div>WALLIX Access Manager no est\u00e1 afectado por esta vulnerabilidad<\/div>\n<\/li>\n<\/ul>\n<div><b>Software fijo<\/b><\/div>\n<ul data-indent-level=\"1\">\n<li>\n<div>WALLIX Bastion 12.0.4, ya disponible https:\/\/updates.wallix.com\/bastion\/bastion-12.0.4.iso<\/div>\n<\/li>\n<li>\n<div>WALLIX Access Manager 5.1.1, ya disponible https:\/\/updates.wallix.com\/accessmanager\/accessmanager-5.1.1.1.iso<\/div>\n<\/li>\n<li>\n<div>WALLIX Bastion 10.0.10, disponible el 22 de noviembre<\/div>\n<\/li>\n<li>\n<div>WALLIX Access Manager 4.0.8, disponible el 22 de noviembre<\/div>\n<\/li>\n<\/ul>\n<div><b>Explotaci\u00f3n y anuncios p\u00fablicos<\/b><\/div>\n<div><\/div>\n<div>WALLIX no tiene conocimiento de ning\u00fan anuncio p\u00fablico o uso malintencionado de la vulnerabilidad que se describe en este aviso.<\/div>\n<div>Sin embargo, se recomienda buscar cualquier actividad anormal en los Bastiones WALLIX.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-5ukex9-47e866328aa8315515063a863ded2438\">\n.avia-section.av-5ukex9-47e866328aa8315515063a863ded2438{\nbackground-color:#ffffff;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_6'  class='avia-section av-5ukex9-47e866328aa8315515063a863ded2438 main_color avia-section-default avia-no-border-styling  avia-builder-el-16  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65\">\n#top .av-special-heading.av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65 .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65 .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65 .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65 .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-42mo9p-f264a8931bc9aee81f92f4d36c0d6c65 av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-17  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >DICIEMBRE 2023 <\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>Posible revelaci\u00f3n de informaci\u00f3n sensible CVE-2023-49961<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><section  class='av_textblock_section av-2xq70d-e5e3fcb56d69531a18fbb3b1f73e2a14 '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><div id=\"UniqueMessageBody\" class=\"XbIp4 jmmB7 GNqVo allowTextSelection OuGoX\" tabindex=\"-1\" role=\"document\" aria-label=\"Corps du message\">\n<div>\n<div>\n<div dir=\"ltr\">\n<div lang=\"fr\">\n<div>\n<div class=\"R1UVb\">\n<div class=\"qF8_5\"><b>RESUMEN<\/b>Se ha descubierto una vulnerabilidad en los productos WALLIX que puede permitir a un atacante acceder a informaci\u00f3n sensible. El atacante podr\u00eda utilizar esta vulnerabilidad para obtener accesos ileg\u00edtimos.WALLIX recomienda aplicar inmediatamente las correcciones publicadas, o antes de su aplicaci\u00f3n, la soluci\u00f3n alternativa descrita a continuaci\u00f3n.<b>Productos afectados<\/b>Todas las versiones compatibles de WALLIX Bastion y Access Manager como dispositivo.<b>Soluciones<\/b>El siguiente art\u00edculo de nuestra base de conocimientos te proporciona el procedimiento de mitigaci\u00f3n.<\/p>\n<ul data-editing-info=\"{\">\n<li>Access Manager como dispositivo: <u>https:\/\/wallix.lightning.force.com\/lightning\/r\/Knowledge__kav\/ka0Sb00000007O5IAI\/view<\/u><\/li>\n<li>Basti\u00f3n: <u>https:\/\/wallix.lightning.force.com\/lightning\/r\/Knowledge__kav\/ka0Sb00000005irIAA\/view<\/u><\/li>\n<\/ul>\n<p><b>Software fijo<\/b>Las versiones Hotfix y los parches est\u00e1n disponibles en nuestro portal de descargas:<\/p>\n<ul data-editing-info=\"{\">\n<li>\n<div>Basti\u00f3n 9.0.9 : https:\/\/cloud.wallix.com\/index.php\/s\/DBkJWdtsPjW7BSn (SHA256: dc5e3fda310a94cd54835800718cc1ec02084a126f79c82dde465eff40d698a4 )<\/div>\n<\/li>\n<li>\n<div>Basti\u00f3n 10.0.5 : https:\/\/cloud.wallix.com\/index.php\/s\/PYjdncJSTaEBRSg (SHA256: 65cdc9b49dfa2160a4a8489fd1c61cad1a48444dbb86cb4a9ac0f4ff527d1197 )<\/div>\n<\/li>\n<\/ul>\n<div><\/div>\n<p><b>Explotaci\u00f3n y Anuncios P\u00fablicos<\/b>WALLIX no tiene conocimiento de ning\u00fan anuncio p\u00fablico o uso malintencionado de la vulnerabilidad que se describe en este aviso.Sin embargo, se recomienda buscar cualquier actividad anormal en los Bastiones WALLIX y en WALLIX Access Manager. Tambi\u00e9n se recomienda asegurarse de que el cortafuegos del Basti\u00f3n y del Gestor de acceso est\u00e1n activados.<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-lyzpdp0i-17b106f359a0a6d9e56ceebb78ad7e69\">\n.avia-section.av-lyzpdp0i-17b106f359a0a6d9e56ceebb78ad7e69{\nbackground-color:#e5e5e5;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_7'  class='avia-section av-lyzpdp0i-17b106f359a0a6d9e56ceebb78ad7e69 main_color avia-section-default avia-no-border-styling  avia-builder-el-19  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c\">\n#top .av-special-heading.av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-49tsz1-aa2b9677a4d6b6dc802e0333e2f5946c av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-20  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >FEBRERO 2023 <\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>Escalada de privilegios de Access Manager CVE-2023-23592<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><section  class='av_textblock_section av-247y9p-abbdfa1fb1e9663efb6218344347f6fd '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><div id=\"UniqueMessageBody\" class=\"XbIp4 jmmB7 GNqVo allowTextSelection OuGoX\" tabindex=\"-1\" role=\"document\" aria-label=\"Corps du message\">\n<div>\n<div>\n<div dir=\"ltr\">\n<div lang=\"fr\">\n<div><b><span lang=\"en-US\">Febrero de 2023<\/span><\/b><b><span lang=\"en-US\">Escalada de privilegios en Access Manager <\/span><\/b><span lang=\"en-US\">CVE-2023-23592<\/span><b><span lang=\"en-US\">RESUMEN<\/span><\/b><span lang=\"en-US\">Se ha descubierto una vulnerabilidad en el producto WALLIX Access Manager que puede permitir a un atacante acceder a informaci\u00f3n sensible. El atacante podr\u00eda utilizar esta vulnerabilidad para obtener<\/span> <span lang=\"en-US\">accesos ileg\u00edtimos. <\/span><span lang=\"en-US\">WALLIX recomienda aplicar inmediatamente las correcciones publicadas, o antes de su aplicaci\u00f3n, la soluci\u00f3n alternativa descrita a continuaci\u00f3n.<\/span><b><span lang=\"en-US\">Productos afectados<\/span><\/b><span lang=\"en-US\">Todas las versiones de WALLIX Access Manager<\/span><span lang=\"en-US\">.<\/span><b><span lang=\"en-US\">Soluciones<\/span><\/b>En el siguiente art\u00edculo de nuestra base de conocimientos encontrar\u00e1 la soluci\u00f3n.https:\/\/support.wallix.com\/s\/article\/How-can-I-mitigate-CVE-2023-23592<b><span lang=\"en-US\">Software fijo<\/span><\/b><span lang=\"en-US\">Las versiones Hotfixes est\u00e1n disponibles en nuestro portal de descargas:<\/span>&#8211; <a href=\"https:\/\/updates.wallix.com\/endpoint\/login?ReturnTo=https%3A%2F%2Fupdates.wallix.com%2Faccessmanager%2Faccessmanager-3.0.16.0.iso&amp;IdP=https%3A%2F%2Fsupport.wallix.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-auth=\"NotApplicable\" data-linkindex=\"1\"><span lang=\"en-US\">Versi\u00f3n 3.0.16<\/span><\/a>&#8211; <a href=\"https:\/\/updates.wallix.com\/endpoint\/login?ReturnTo=https%3A%2F%2Fupdates.wallix.com%2Faccessmanager%2Faccessmanager-4.0.3.2.iso&amp;IdP=https%3A%2F%2Fsupport.wallix.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-auth=\"NotApplicable\" data-linkindex=\"2\"><span lang=\"en-US\">Versi\u00f3n 4.0.3<\/span><\/a><b><span lang=\"en-US\">Explotaci\u00f3n y anuncios p\u00fablicos<\/span><\/b><span lang=\"en-US\">WALLIX no tiene conocimiento de ning\u00fan anuncio p\u00fablico o uso malintencionado de la vulnerabilidad que se describe en este aviso. Sin embargo, se recomienda buscar cualquier actividad anormal en los WALLIX Bastions que est\u00e9n conectados a WALLIX Access Manager. En particular, se recomienda buscar IP inusuales utilizadas por usuarios con privilegios que puedan ser utilizadas por m\u00faltiples cuentas de usuario.<\/span><b><span lang=\"en-US\">Fuente<\/span><\/b><span lang=\"en-US\">Controles internos de seguridad<\/span><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div><div id='av_section_8'  class='avia-section av-29k7kd-e04265b670bddc0f466d80c0b864b53f main_color avia-section-default avia-no-border-styling  avia-builder-el-22  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7\">\n#top .av-special-heading.av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7 .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7 .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7 .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7 .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-4ioy65-a028bb3c2b857054ec6c1af3531b4fe7 av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-23  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >DICIEMBRE 2021<\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>Vulnerabilidad de ejecuci\u00f3n remota de c\u00f3digo en Log4J (CVE-2021-44228)<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><section  class='av_textblock_section av-2zscrh-0a2cb36181c2906b0431e672434bd74f '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><p><strong>RESUMEN<\/strong>El equipo de seguridad de Alibaba Cloud public\u00f3 el 9 de diciembre de 2021 una vulnerabilidad en log4j, una biblioteca de registro com\u00fan de Java. (CVE-2021-44228) Esta vulnerabilidad permite la ejecuci\u00f3n remota de c\u00f3digo no autenticado en aplicaciones Java.<strong>Productos afectados<\/strong>Todas las versiones de WALLIX Access Manager<strong>Soluciones<\/strong>La configuraci\u00f3n por defecto de WALLIX Access Manager impide explotar dicha vulnerabilidad en el campo de login.Sin embargo, para evitar cualquier posibilidad de encontrar un exploit en caso de modificaci\u00f3n de la configuraci\u00f3n por defecto del WALLIX Access Manager, el equipo de WALLIX propone un parche que desactiva la clase defectuosa de la biblioteca log4j.Este parche se aplica a todas las versiones de Access Manager a partir de la versi\u00f3n 2.0.El siguiente art\u00edculo de nuestra base de conocimientos le proporciona el acceso al parche, as\u00ed como el procedimiento para instalarlo.<a href=\"https:\/\/support.wallix.com\/s\/article\/CVE-2021-44228-Mitigation-procedure\">https:\/\/support.wallix.com\/s\/article\/CVE-2021-44228-Mitigation-procedure<\/a><strong>Software fijo<\/strong>Est\u00e1 prevista una actualizaci\u00f3n de la versi\u00f3n Log4J junto con la versi\u00f3n 3.0.11 de Access Manager.Est\u00e1 previsto que esta versi\u00f3n salga a la venta a finales de diciembre de 2021.<strong>Explotaci\u00f3n y anuncios p\u00fablicos<\/strong>WALLIX no tiene conocimiento de ning\u00fan anuncio p\u00fablico o uso malintencionado de la vulnerabilidad que se describe en este aviso. Sin embargo, se recomienda buscar cualquier actividad anormal en los WALLIX Bastions que est\u00e9n conectados a WALLIX Access Manager. En particular se recomienda buscar la creaci\u00f3n de nuevos usuarios o autorizaciones especialmente desde la publicaci\u00f3n del CVE<strong>Fuente<\/strong>El equipo de seguridad de Alibaba Cloud public\u00f3 el 9 de diciembre de 2021 una vulnerabilidad en log4j, una biblioteca de registro com\u00fan de Java. (CVE-2021-44228)<\/p>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-lpmr1ai0-b6ec89c5c2384aac021f6ef550a9b8e8\">\n.avia-section.av-lpmr1ai0-b6ec89c5c2384aac021f6ef550a9b8e8{\nbackground-color:#e8e8e8;\nbackground-image:unset;\n}\n<\/style>\n<div id='av_section_9'  class='avia-section av-lpmr1ai0-b6ec89c5c2384aac021f6ef550a9b8e8 main_color avia-section-default avia-no-border-styling  avia-builder-el-25  el_after_av_section  el_before_av_section  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-9lz3x-76392e038bf6393d0b621d954b5b18fe\">\n#top .av-special-heading.av-9lz3x-76392e038bf6393d0b621d954b5b18fe{\npadding-bottom:30px;\ncolor:#172542;\nfont-size:30px;\n}\nbody .av-special-heading.av-9lz3x-76392e038bf6393d0b621d954b5b18fe .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-9lz3x-76392e038bf6393d0b621d954b5b18fe .av-special-heading-tag{\nfont-size:30px;\n}\n.av-special-heading.av-9lz3x-76392e038bf6393d0b621d954b5b18fe .special-heading-inner-border{\nborder-color:#172542;\n}\n.av-special-heading.av-9lz3x-76392e038bf6393d0b621d954b5b18fe .av-subheading{\nfont-size:18px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-9lz3x-76392e038bf6393d0b621d954b5b18fe .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-9lz3x-76392e038bf6393d0b621d954b5b18fe .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-9lz3x-76392e038bf6393d0b621d954b5b18fe av-special-heading-h2 custom-color-heading blockquote modern-quote  avia-builder-el-26  el_before_av_textblock  avia-builder-el-first  av-inherit-size'><h2 class='av-special-heading-tag '  itemprop=\"headline\"  >ENERO 2021 <\/h2><div class='av_custom_color av-subheading av-subheading_below'><p>Escalada de privilegios Sudo que afecta a los productos WALLIX &#8211; CVE-2021-3156<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><section  class='av_textblock_section av-lmrwq1h4-e30c9b734003b6ed2e3f4144838826ff '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/CreativeWork\" ><div class='avia_textblock'  itemprop=\"text\" ><h6><span style=\"color: #f4813a;\">RESUMEN<\/span><\/h6>\n<p>El equipo de investigaci\u00f3n de Qualys ha descubierto una vulnerabilidad de desbordamiento de heap en sudo (CVE-2021-3156), cualquier usuario local sin privilegios puede obtener privilegios de root en un host vulnerable utilizando una configuraci\u00f3n por defecto de sudo explotando esta vulnerabilidad.sudo s\u00f3lo puede ser explotado localmente. Esto significa que :<\/p>\n<ul>\n<li>El usuario se conecta en el WALLIX Bastion, a trav\u00e9s de la cuenta wabadmin, en la interfaz de administraci\u00f3n. Este usuario puede entonces explotar sudo para convertirse en root y saltarse todas las seguridades de WALLIX Bastion<\/li>\n<li>Existe una vulnerabilidad de Explotaci\u00f3n Remota de C\u00f3digo (RCE) en otra pieza de software WALLIX o de terceros, que proporcionar\u00e1 un shell local. Despu\u00e9s de explotar con \u00e9xito esta vulnerabilidad, el atacante ser\u00e1 capaz de explotar sudo para convertirse en root. Que WALLIX sepa, un Bastion actualizado no tiene tal vulnerabilidad.<\/li>\n<\/ul>\n<h6>Productos afectados<\/h6>\n<ul>\n<li>Todas las versiones anteriores a WALLIX Bastion 8.0.6 (incluida)<\/li>\n<li>Todas las versiones 8.1 y 8.2<\/li>\n<\/ul>\n<h6>Soluciones<\/h6>\n<p>Esta vulnerabilidad no tiene soluci\u00f3n.<\/p>\n<h6>Software fijo<\/h6>\n<p>Esta vulnerabilidad est\u00e1 solucionada a partir de la versi\u00f3n 8.0.7 y 7.0.14 de WALLIX Bastion.<\/p>\n<ul>\n<li>Hay un parche de correcci\u00f3n disponible para la versi\u00f3n 8.0.6 y anteriores (se aplica a las versiones 8.1 y 8.2)<\/li>\n<li>Hay disponible un parche Fix para la versi\u00f3n 7.0.13 y anteriores<\/li>\n<\/ul>\n<p>Estos elementos est\u00e1n disponibles en nuestro sitio de descargas : <span style=\"color: #f4913a;\"><a style=\"color: #f4913a;\" href=\"https:\/\/support.wallix.com\/s\/article\/Patch-for-Sudo-vulnerability-CVE-2021-3156\" target=\"_blank\" rel=\"noopener noreferrer\" data-auth=\"NotApplicable\">Soporte WALLIX: Parches<\/a><\/span><\/p>\n<h6>Explotaci\u00f3n y anuncios p\u00fablicos<\/h6>\n<p>WALLIX no tiene conocimiento de ning\u00fan anuncio p\u00fablico o uso malintencionado de la vulnerabilidad que se describe en este aviso.<\/p>\n<h6>Fuente<\/h6>\n<p>El 26 de enero de 2021, Qualys revel\u00f3 p\u00fablicamente esta vulnerabilidad en un bolet\u00edn de seguridad en el siguiente enlace: <a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2021\/01\/26\/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit\" target=\"_blank\" rel=\"noopener noreferrer\" data-auth=\"NotApplicable\">https:\/\/blog.qualys.com<\/a><\/p>\n<\/div><\/section><\/div><\/div><\/div><!-- close content main div --><\/div><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-ogks99-ce4f98266b381d0663d4404da1b45671\">\n.avia-section.av-ogks99-ce4f98266b381d0663d4404da1b45671{\nbackground-color:#1e91ad;\nbackground:linear-gradient( to bottom, #1e91ad, #172542 );\n}\n<\/style>\n<div id='av_section_10'  class='avia-section av-ogks99-ce4f98266b381d0663d4404da1b45671 main_color avia-section-large avia-no-border-styling  avia-builder-el-28  el_after_av_section  avia-builder-el-last  avia-bg-style-scroll container_wrap fullsize'  ><div class='container av-section-cont-open' ><div class='template-page content  av-content-full alpha units'><div class='post-entry post-entry-type-page post-entry-41732'><div class='entry-content-wrapper clearfix'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e\">\n#top .av-special-heading.av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e{\npadding-bottom:0;\ncolor:#ffffff;\nfont-size:37px;\n}\nbody .av-special-heading.av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e .av-special-heading-tag{\nfont-size:37px;\n}\n.av-special-heading.av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e .special-heading-inner-border{\nborder-color:#ffffff;\n}\n.av-special-heading.av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e .av-subheading{\nfont-size:26px;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-lr7zf1-dd0516c13d9324ceecfdb22669e4360e av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered  avia-builder-el-29  el_before_av_one_fourth  avia-builder-el-first  av-inherit-size'><h3 class='av-special-heading-tag '  itemprop=\"headline\"  >ASISTENCIA Y SERVICIOS WALLIX<\/h3><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><div class='flex_column_table av-koqb5p-7b5560d5d94e8a3834f17d963de96b99 sc-av_one_fourth av-equal-height-column-flextable'>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-koqb5p-7b5560d5d94e8a3834f17d963de96b99\">\n.flex_column.av-koqb5p-7b5560d5d94e8a3834f17d963de96b99{\nwidth:23.125%;\nmargin-left:0;\npadding:20px 20px 20px 20px;\n}\n#top .flex_column_table.av-equal-height-column-flextable.av-koqb5p-7b5560d5d94e8a3834f17d963de96b99 .av-flex-placeholder{\nwidth:2.5%;\n}\n<\/style>\n<div  class='flex_column av-koqb5p-7b5560d5d94e8a3834f17d963de96b99 av_one_fourth  avia-builder-el-30  el_after_av_heading  el_before_av_one_fourth  first flex_column_table_cell av-equal-height-column av-align-top av-animated-generic bottom-to-top  '     ><p>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51\">\n#top .av-special-heading.av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51{\nmargin:5px 5px 5px 5px;\npadding-bottom:10px;\ncolor:#ffffff;\nfont-size:24px;\n}\nbody .av-special-heading.av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51 .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51 .av-special-heading-tag{\nfont-size:24px;\n}\n.av-special-heading.av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51 .special-heading-inner-border{\nborder-color:#ffffff;\n}\n.av-special-heading.av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51 .av-subheading{\nfont-size:16px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-1yiekt-8fff00eed5e23b06d60f44cfee17fb51 av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered  avia-builder-el-31  el_before_av_button  avia-builder-el-first  av-inherit-size'><h3 class='av-special-heading-tag '  itemprop=\"headline\"  >WALLIXCONSULTOR\u00cdA<\/h3><div class='av_custom_color av-subheading av-subheading_below'><p>Pensar, dise\u00f1ar y asegurar implantaciones complejas o de gran envergadura<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><div  class='avia-button-wrap av-h9dibx-5ab6568d900f801992a81c145710eadf-wrap avia-button-center  avia-builder-el-32  el_after_av_heading  avia-builder-el-last '>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-h9dibx-5ab6568d900f801992a81c145710eadf\">\n#top #wrap_all .avia-button.av-h9dibx-5ab6568d900f801992a81c145710eadf{\nbackground-color:#ec6707;\nborder-color:#ea6e52;\ncolor:#ffffff;\nborder-style:solid;\nborder-width:1px 1px 1px 1px;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-h9dibx-5ab6568d900f801992a81c145710eadf:hover{\nbackground-color:#ffffff;\ncolor:#f17c00;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-h9dibx-5ab6568d900f801992a81c145710eadf .avia-svg-icon svg:first-child{\nfill:#ffffff;\nstroke:#ffffff;\n}\n#top #wrap_all .avia-button.av-h9dibx-5ab6568d900f801992a81c145710eadf:hover .avia-svg-icon svg:first-child{\nfill:#f17c00;\nstroke:#f17c00;\n}\n<\/style>\n<a href='https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/consultoria\/'  class='avia-button av-h9dibx-5ab6568d900f801992a81c145710eadf av-link-btn avia-icon_select-no avia-size-large avia-position-center'  target=\"_blank\"  rel=\"noopener noreferrer\"  aria-label=\"CONSULTOR\u00cdA\"><span class='avia_iconbox_title' >CONSULTOR\u00cdA<\/span><\/a><\/div><\/p><\/div><div class='av-flex-placeholder'><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-1mkvm5-051e82c05dfa1f80d127cd8444933506\">\n.flex_column.av-1mkvm5-051e82c05dfa1f80d127cd8444933506{\nwidth:23.125%;\nmargin-left:0;\npadding:20px 20px 20px 20px;\n}\n#top .flex_column_table.av-equal-height-column-flextable.av-1mkvm5-051e82c05dfa1f80d127cd8444933506 .av-flex-placeholder{\nwidth:2.5%;\n}\n<\/style>\n<div  class='flex_column av-1mkvm5-051e82c05dfa1f80d127cd8444933506 av_one_fourth  avia-builder-el-33  el_after_av_one_fourth  el_before_av_one_fourth  flex_column_table_cell av-equal-height-column av-align-top av-animated-generic bottom-to-top  '     ><p>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-ev5q7x-737935db2154ff2773fd032b6dd0ca88\">\n#top .av-special-heading.av-ev5q7x-737935db2154ff2773fd032b6dd0ca88{\nmargin:5px 5px 5px 5px;\npadding-bottom:10px;\ncolor:#ffffff;\nfont-size:24px;\n}\nbody .av-special-heading.av-ev5q7x-737935db2154ff2773fd032b6dd0ca88 .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-ev5q7x-737935db2154ff2773fd032b6dd0ca88 .av-special-heading-tag{\nfont-size:24px;\n}\n.av-special-heading.av-ev5q7x-737935db2154ff2773fd032b6dd0ca88 .special-heading-inner-border{\nborder-color:#ffffff;\n}\n.av-special-heading.av-ev5q7x-737935db2154ff2773fd032b6dd0ca88 .av-subheading{\nfont-size:16px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-ev5q7x-737935db2154ff2773fd032b6dd0ca88 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-ev5q7x-737935db2154ff2773fd032b6dd0ca88 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-ev5q7x-737935db2154ff2773fd032b6dd0ca88 av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered  avia-builder-el-34  el_before_av_button  avia-builder-el-first  av-inherit-size'><h3 class='av-special-heading-tag '  itemprop=\"headline\"  >ATENCI\u00d3N AL CLIENTE<\/h3><div class='av_custom_color av-subheading av-subheading_below'><p>Ponte en contactocon el equipo de atenci\u00f3n al cliente<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><div  class='avia-button-wrap av-c296m5-8c4a1d28ba9bbd1a2a9891b3ec9bcbad-wrap avia-button-center  avia-builder-el-35  el_after_av_heading  avia-builder-el-last '>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-c296m5-8c4a1d28ba9bbd1a2a9891b3ec9bcbad\">\n#top #wrap_all .avia-button.av-c296m5-8c4a1d28ba9bbd1a2a9891b3ec9bcbad{\nbackground-color:#ec6707;\nborder-color:#ea6e52;\ncolor:#ffffff;\nborder-style:solid;\nborder-width:1px 1px 1px 1px;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-c296m5-8c4a1d28ba9bbd1a2a9891b3ec9bcbad:hover{\nbackground-color:#ffffff;\ncolor:#f17c00;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-c296m5-8c4a1d28ba9bbd1a2a9891b3ec9bcbad .avia-svg-icon svg:first-child{\nfill:#ffffff;\nstroke:#ffffff;\n}\n#top #wrap_all .avia-button.av-c296m5-8c4a1d28ba9bbd1a2a9891b3ec9bcbad:hover .avia-svg-icon svg:first-child{\nfill:#f17c00;\nstroke:#f17c00;\n}\n<\/style>\n<a href='https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/atencion-al-cliente\/'  class='avia-button av-c296m5-8c4a1d28ba9bbd1a2a9891b3ec9bcbad av-link-btn avia-icon_select-no avia-size-large avia-position-center'  target=\"_blank\"  rel=\"noopener noreferrer\"  aria-label=\"ATENCI\u00d3N AL CLIENTE\"><span class='avia_iconbox_title' >ATENCI\u00d3N AL CLIENTE<\/span><\/a><\/div><\/p><\/div><div class='av-flex-placeholder'><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-a7n7gd-648c6f678794c5b9b48971087f36ed59\">\n.flex_column.av-a7n7gd-648c6f678794c5b9b48971087f36ed59{\nwidth:23.125%;\nmargin-left:0;\npadding:20px 20px 20px 20px;\n}\n#top .flex_column_table.av-equal-height-column-flextable.av-a7n7gd-648c6f678794c5b9b48971087f36ed59 .av-flex-placeholder{\nwidth:2.5%;\n}\n<\/style>\n<div  class='flex_column av-a7n7gd-648c6f678794c5b9b48971087f36ed59 av_one_fourth  avia-builder-el-36  el_after_av_one_fourth  el_before_av_one_fourth  flex_column_table_cell av-equal-height-column av-align-top av-animated-generic bottom-to-top  '     ><p>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-vvsul-cf205b74ea0abf736a48f12af40864f8\">\n#top .av-special-heading.av-vvsul-cf205b74ea0abf736a48f12af40864f8{\nmargin:5px 5px 5px 5px;\npadding-bottom:10px;\ncolor:#ffffff;\nfont-size:24px;\n}\nbody .av-special-heading.av-vvsul-cf205b74ea0abf736a48f12af40864f8 .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-vvsul-cf205b74ea0abf736a48f12af40864f8 .av-special-heading-tag{\nfont-size:24px;\n}\n.av-special-heading.av-vvsul-cf205b74ea0abf736a48f12af40864f8 .special-heading-inner-border{\nborder-color:#ffffff;\n}\n.av-special-heading.av-vvsul-cf205b74ea0abf736a48f12af40864f8 .av-subheading{\nfont-size:16px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-vvsul-cf205b74ea0abf736a48f12af40864f8 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-vvsul-cf205b74ea0abf736a48f12af40864f8 .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-vvsul-cf205b74ea0abf736a48f12af40864f8 av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered  avia-builder-el-37  el_before_av_button  avia-builder-el-first  av-inherit-size'><h3 class='av-special-heading-tag '  itemprop=\"headline\"  >SERVICIOS PROFESIONALES<\/h3><div class='av_custom_color av-subheading av-subheading_below'><p>Implantaci\u00f3n, auditor\u00eda y asistencia para las soluciones WALLIX<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><div  class='avia-button-wrap av-775665-45de69dacb1cd08e3015de6d187d66f0-wrap avia-button-center  avia-builder-el-38  el_after_av_heading  avia-builder-el-last '>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-775665-45de69dacb1cd08e3015de6d187d66f0\">\n#top #wrap_all .avia-button.av-775665-45de69dacb1cd08e3015de6d187d66f0{\nbackground-color:#ec6707;\nborder-color:#ea6e52;\ncolor:#ffffff;\nborder-style:solid;\nborder-width:1px 1px 1px 1px;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-775665-45de69dacb1cd08e3015de6d187d66f0:hover{\nbackground-color:#ffffff;\ncolor:#f17c00;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-775665-45de69dacb1cd08e3015de6d187d66f0 .avia-svg-icon svg:first-child{\nfill:#ffffff;\nstroke:#ffffff;\n}\n#top #wrap_all .avia-button.av-775665-45de69dacb1cd08e3015de6d187d66f0:hover .avia-svg-icon svg:first-child{\nfill:#f17c00;\nstroke:#f17c00;\n}\n<\/style>\n<a href='https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/servicios-profesionales\/'  class='avia-button av-775665-45de69dacb1cd08e3015de6d187d66f0 av-link-btn avia-icon_select-no avia-size-large avia-position-center'  target=\"_blank\"  rel=\"noopener noreferrer\"  aria-label=\"SERVICIOS PROFESIONALES\"><span class='avia_iconbox_title' >SERVICIOS PROFESIONALES<\/span><\/a><\/div><\/p><\/div><div class='av-flex-placeholder'><\/div>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-5l8jvh-4926330bb5166149bc14493c9e84dfe8\">\n.flex_column.av-5l8jvh-4926330bb5166149bc14493c9e84dfe8{\nwidth:23.125%;\nmargin-left:0;\npadding:20px 20px 20px 20px;\n}\n#top .flex_column_table.av-equal-height-column-flextable.av-5l8jvh-4926330bb5166149bc14493c9e84dfe8 .av-flex-placeholder{\nwidth:2.5%;\n}\n<\/style>\n<div  class='flex_column av-5l8jvh-4926330bb5166149bc14493c9e84dfe8 av_one_fourth  avia-builder-el-39  el_after_av_one_fourth  avia-builder-el-last  flex_column_table_cell av-equal-height-column av-align-top av-animated-generic bottom-to-top  '     ><p>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-472zvh-b6c4db9d147db50d23697e7383b80d0e\">\n#top .av-special-heading.av-472zvh-b6c4db9d147db50d23697e7383b80d0e{\nmargin:5px 5px 5px 5px;\npadding-bottom:10px;\ncolor:#ffffff;\nfont-size:24px;\n}\nbody .av-special-heading.av-472zvh-b6c4db9d147db50d23697e7383b80d0e .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n#top #wrap_all .av-special-heading.av-472zvh-b6c4db9d147db50d23697e7383b80d0e .av-special-heading-tag{\nfont-size:24px;\n}\n.av-special-heading.av-472zvh-b6c4db9d147db50d23697e7383b80d0e .special-heading-inner-border{\nborder-color:#ffffff;\n}\n.av-special-heading.av-472zvh-b6c4db9d147db50d23697e7383b80d0e .av-subheading{\nfont-size:16px;\ncolor:#ec6707;\n}\n\n@media only screen and (min-width: 480px) and (max-width: 767px){ \n#top #wrap_all .av-special-heading.av-472zvh-b6c4db9d147db50d23697e7383b80d0e .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n\n@media only screen and (max-width: 479px){ \n#top #wrap_all .av-special-heading.av-472zvh-b6c4db9d147db50d23697e7383b80d0e .av-special-heading-tag{\nfont-size:0.8em;\n}\n}\n<\/style>\n<div  class='av-special-heading av-472zvh-b6c4db9d147db50d23697e7383b80d0e av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered  avia-builder-el-40  el_before_av_button  avia-builder-el-first  av-inherit-size'><h3 class='av-special-heading-tag '  itemprop=\"headline\"  >ACADEMIA WALLIX<\/h3><div class='av_custom_color av-subheading av-subheading_below'><p>Formaci\u00f3n y certificaciones para socios y usuarios finales<\/p>\n<\/div><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div><div  class='avia-button-wrap av-20pa31-96d6be0619bb1bb460319492cd69f516-wrap avia-button-center  avia-builder-el-41  el_after_av_heading  avia-builder-el-last '>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-20pa31-96d6be0619bb1bb460319492cd69f516\">\n#top #wrap_all .avia-button.av-20pa31-96d6be0619bb1bb460319492cd69f516{\nbackground-color:#ec6707;\nborder-color:#ea6e52;\ncolor:#ffffff;\nborder-style:solid;\nborder-width:1px 1px 1px 1px;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-20pa31-96d6be0619bb1bb460319492cd69f516:hover{\nbackground-color:#ffffff;\ncolor:#f17c00;\ntransition:all 0.4s ease-in-out;\n}\n#top #wrap_all .avia-button.av-20pa31-96d6be0619bb1bb460319492cd69f516 .avia-svg-icon svg:first-child{\nfill:#ffffff;\nstroke:#ffffff;\n}\n#top #wrap_all .avia-button.av-20pa31-96d6be0619bb1bb460319492cd69f516:hover .avia-svg-icon svg:first-child{\nfill:#f17c00;\nstroke:#f17c00;\n}\n<\/style>\n<a href='https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/wallix-academy\/'  class='avia-button av-20pa31-96d6be0619bb1bb460319492cd69f516 av-link-btn avia-icon_select-no avia-size-large avia-position-center'  target=\"_blank\"  rel=\"noopener noreferrer\"  aria-label=\"FORMACI\u00d3N\"><span class='avia_iconbox_title' >FORMACI\u00d3N<\/span><\/a><\/div><\/p><\/div><\/div><!--close column table wrapper. Autoclose: 1 --><\/changed><\/ip><\/actor><\/name><\/object><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":3,"featured_media":0,"parent":41717,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-41732","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Alertas y avisos - Ciberseguridad<\/title>\n<meta name=\"description\" content=\"Importante: Mant\u00e9ngase al d\u00eda de las \u00faltimas alertas y avisos de seguridad para las soluciones WALLIX. No se lo pierda.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Alertas y avisos - Ciberseguridad\" \/>\n<meta property=\"og:description\" content=\"Importante: Mant\u00e9ngase al d\u00eda de las \u00faltimas alertas y avisos de seguridad para las soluciones WALLIX. No se lo pierda.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/\" \/>\n<meta property=\"og:site_name\" content=\"WALLIX\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-17T15:12:42+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@wallixcom\" \/>\n<meta name=\"twitter:label1\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data1\" content=\"17 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/asistencia-y-servicios\\\/alertas-y-avisos\\\/\",\"url\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/asistencia-y-servicios\\\/alertas-y-avisos\\\/\",\"name\":\"Alertas y avisos - Ciberseguridad\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/#website\"},\"datePublished\":\"2024-01-23T14:48:40+00:00\",\"dateModified\":\"2026-07-17T15:12:42+00:00\",\"description\":\"Importante: Mant\u00e9ngase al d\u00eda de las \u00faltimas alertas y avisos de seguridad para las soluciones WALLIX. No se lo pierda.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/asistencia-y-servicios\\\/alertas-y-avisos\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.wallix.com\\\/es\\\/asistencia-y-servicios\\\/alertas-y-avisos\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/asistencia-y-servicios\\\/alertas-y-avisos\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/cybersecurity-simplified\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ASISTENCIA Y SERVICIOS\",\"item\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/asistencia-y-servicios\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Alertas y avisos\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/\",\"name\":\"WALLIX\",\"description\":\"CYBERSECURITY SIMPLIFIED\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.wallix.com\\\/es\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Alertas y avisos - Ciberseguridad","description":"Importante: Mant\u00e9ngase al d\u00eda de las \u00faltimas alertas y avisos de seguridad para las soluciones WALLIX. No se lo pierda.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/","og_locale":"es_ES","og_type":"article","og_title":"Alertas y avisos - Ciberseguridad","og_description":"Importante: Mant\u00e9ngase al d\u00eda de las \u00faltimas alertas y avisos de seguridad para las soluciones WALLIX. No se lo pierda.","og_url":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/","og_site_name":"WALLIX","article_modified_time":"2026-07-17T15:12:42+00:00","twitter_card":"summary_large_image","twitter_site":"@wallixcom","twitter_misc":{"Tiempo de lectura":"17 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/","url":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/","name":"Alertas y avisos - Ciberseguridad","isPartOf":{"@id":"https:\/\/www.wallix.com\/es\/#website"},"datePublished":"2024-01-23T14:48:40+00:00","dateModified":"2026-07-17T15:12:42+00:00","description":"Importante: Mant\u00e9ngase al d\u00eda de las \u00faltimas alertas y avisos de seguridad para las soluciones WALLIX. No se lo pierda.","breadcrumb":{"@id":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/alertas-y-avisos\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.wallix.com\/es\/cybersecurity-simplified\/"},{"@type":"ListItem","position":2,"name":"ASISTENCIA Y SERVICIOS","item":"https:\/\/www.wallix.com\/es\/asistencia-y-servicios\/"},{"@type":"ListItem","position":3,"name":"Alertas y avisos"}]},{"@type":"WebSite","@id":"https:\/\/www.wallix.com\/es\/#website","url":"https:\/\/www.wallix.com\/es\/","name":"WALLIX","description":"CYBERSECURITY SIMPLIFIED","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wallix.com\/es\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"}]}},"_links":{"self":[{"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/pages\/41732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/comments?post=41732"}],"version-history":[{"count":28,"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/pages\/41732\/revisions"}],"predecessor-version":[{"id":92051,"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/pages\/41732\/revisions\/92051"}],"up":[{"embeddable":true,"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/pages\/41717"}],"wp:attachment":[{"href":"https:\/\/www.wallix.com\/es\/wp-json\/wp\/v2\/media?parent=41732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}