Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 14 May


Monthly Patches are out for Siemens and SAP. New Alerts for Apple, Google Chrome (Exploit), Extreme Networks, Cacti, and Linux.

Apple 

Apple has published updates for iOS, iPadOS, macOS, watchOS, tvOS, and Safari. One exploited vulnerability is patched for older versions of macOS and iOS.
More info. And here.

Siemens 

Siemens Monthly Patches are out with 38 bulletins, 15 new bulletins and 23 updated bulletins. Of the new bulletins, highest CVSSv3 score of 10.
More info.

SIMATIC CN 4100 is vulnerable to use of hard coded credentials including root user. Highest CVSSv3 score of 10.
More info.

Siemens has released a new version for SIMATIC RTLS Locating Manager that fixes several security vulnerabilities. Highest CVSSv3 score of 10.
More info.

Several products used in Desigo Fire Safety UL and Cerberus PRO UL Fire Protection Systems contain buffer overflow vulnerabilities. Highest CVSSv3 score of 10.
More info.

The RUGGEDCOM CROSSBOW server application contains multiple vulnerabilities that could allow a remote attacker to execute arbitrary database queries or upload arbitrary files. Highest CVSSv3 score of 9.8
More info.

Siemens has released a new version for RUGGEDCOM APE1808 that corrects vulnerabilities in Nozomi Guardian/CMC. Highest CVSSv3 score of 7.5
More info.

SAP 

SAP Security Patch Day saw the release of 14 new Security Notes 3 updates. Of the new Notes, highest CVSSv3 score of 9.8
More info.

Google Exploit

Google has published an update for Chrome for Desktop that fixes one vulnerability that is currently being exploited.
More info.

Microsoft is aware. More info.

Extreme Networks 

Extreme Networks was unable to publish security bulletins to the public portal for the first part of the year, and have now made 50 advisories for 2024 available.
More info.

Cacti 

Cacti has published an update that fixes 9 security vulnerabilities, including several RCE vulnerabilities.
More info.

Linux 

Ubuntu has updated the kernel. More info.
Amazon Linux has updated the kernel. More info.
Amazon Linux 2023 has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Friday, 01 November 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/