CND News and Blog
Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Zoom, PowerDNS, Dell, and HIMA. Monthly Patches for Microsoft and Adobe are expected this afternoon, along with Node.js patches. Siemens Siemens Monthly Patches include 15 new bulletins and 8 updated bulletins. Of the new bulletins, Highest CVSSv3 score of 9.8Mor...
New Alert for Linux. Enjoy your Monday, tomorrow is Patch Tuesday and the awaited Node.js security update. Linux Oracle Linux has updated the kernel. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version o...
Monthly Patches are out for Fortinet. New Alerts for Microsoft Edge, Dell, Ivanti, Wind River, and Linux. Fortinet Fortinet has published 7 bulletins in their Monthly Patches for their products. Highest CVSSv3 score of 9.8More info.A use of externally-controlled format string vulnerability in FortiOS fgfmd daemon may allow a remote attacker t...
New Alerts for Cisco, ClamAV, SonicWall, IBM, NetApp, Django, and Linux. Cisco Multiple vulnerabilities in the Cisco Expressway Series could allow a remote attacker to conduct CSRF attacks, which could allow the attacker to perform arbitrary actions on an affected device. CVSSv3 score of 9.6More info.Secure Endpoint products are affected by a...
New Alerts for Google Chrome, Fortinet, Badger Meter, Hitachi, Canon, Juniper Networks, Linux Shim, and Linux distros. Google Google has updated Chrome for Desktop to fix 3 vulnerabilities, at least 2 rated High.More info. Fortinet Fortinet has added two vulnerabilities to a 2023 bulletin. FortiSIEM supervisor may allow a remote attacke...
Monthly Patches are out for Qualcomm, Google Android, Google Pixel, and Samsung. New Alerts for Pilz, B&R Automation, and HPE. Qualcomm Monthly Patches are out for Qualcomm including 17vulnerabilities, 16 rated High, and 1 rated Moderate. Highest CVSSv3 score of 9.3More info. Google Android Monthly Patches are out, with 15 vulnerabi...
Monthly Patches are out for MediaTek. New Alerts for ManageEngine, HCL Software, Dell, and QNAP. Qualcomm Monthly Patches are expected out today as well. ManageEngine Several ManageEngine products are affected by the recent Apache Tomcat vulnerability. CVSSv3 score of 5.3.More info. HCL Software HCL BigFix Platform has addressed m...
New Alerts for Gessler, Microsoft Edge, Dell, and NetApp. Gessler WEB-MASTER contains two vulnerabilities, including Use of Weak Credentials, and Use of Weak Hash. Highest CVSSv3 score of 9.8Patches are available, but must be applied by Gessler technicians.More info. Microsoft Microsoft has updated Edge for the recently reported chromiu...
New Alerts for Baxter, Meinberg, Apple Vision Pro (Exploit), IBM, Dell, and NetApp. Baxter Baxter has published a list of products distributed by Baxter that are vulnerable to the Mirth Connect RCE. CVSSv3 score of 9.8Some patches are available, others are expected Q1 2024.More info. Meinberg Meinberg has updated LANTIME firmware to fix...
New Alerts for Google Chrome, Emerson, Rockwell Automation, Trend Micro, Salt, SICK, and SuperMicro. Google Google has updated Chrome for Desktop to fix 4 security vulnerabilities. More info. Emerson Four vulnerabilities exist in Rosemount Gas Chromatographs that allow for a remote attacker to run arbitrary commands in root context, to ...
New Alerts for Festo, Mitsubishi Electric, Hitachi Energy, Hitachi, and Linux. Festo Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to RCE or DoS. Highest CVSSv3 score of 8.8More info. Mitsubishi Electric Authentication bypass and RCE vulnerabilities exist in multiple FA engineering software products. ...
New Alerts for FFmpeg, SE-elektronic, TRUMPF, Dell, HP, Juniper Networks, and Linux. FFmpeg Two vulnerabilities in FFmpeg allow a remote attacker to conduct RCE and achieve DoS. Highest CVSSv3 score of 9.8More info. And here. SE-elektronic E-DDC3.3 contains 2 vulnerabilities, one of which could allow a remote attacker to achieve RCE. Hi...
New Alerts for SystemK (Exploit), Microsoft Edge, Lexmark, GnuPG, and Linux. SystemK Exploit NVR 504/508/516 contains a command injection vulnerability that could allow a remote attacker to execute commands with root privileges. CVSSv3 score of 9.8PoC exists. No response from vendor.More info. Microsoft Microsoft has updated Edge to correct t...
New Alerts for Cisco, HMS, Softing, Dell, HP, NetApp, and Linux. Cisco Cisco has published 3 new bulletins, highest CVSSv3 score of 9.9More info.A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow a remote attacker to execute arbitrary code on an affected device. CVSSv3 score of 9.9More i...
New Alerts for Google Chrome, Voltronic Power, Fortra, and Linux. Google Google has updated Chrome for Desktop to fix 17 security vulnerabilities, several rated High.More info. And here. Voltronic Power ViewPower Pro contains several vulnerabilities, including Deserialization of Untrusted Data, Missing Authentication for Critical Functi...
New Alerts for Apple (Exploit), Splunk, TRUMPF, HPE, Mozilla, and Linux. Apple Exploit Apple has published updates for Safari, iOS, iPadOS, macOS, watchOS, and tvOS to fix 29 vulnerabilities among them, 3 of which are being exploited. Highest CVSSv3 score of 9.8More info. And here. Splunk Splunk has published 4 new security bulletins covering...
New Alerts for Spring, WAGO, and Juniper Networks. Spring Spring Framework allows a remote attacker to provide specially crafted HTTP requests that may cause a DoS. CVSSv3 score of 7.5More info. WAGO A heap-based buffer overflow is possible in CodeMeter Runtime affecting multiple products by WAGO. CVSSv3 score of 9.8More info. Jun...
New Alerts for AVEVA, Apache Tomcat, NetApp, and Linux. AVEVA PI Server contains several vulnerabilities that could allow a remote attacker to crash the product or throttle the memory leading to a partial DoS. CVSSv3 score of 7.5More info. And here. Apache Tomcat contains an Information Disclosure vulnerability. CVSSv3 score of 7.5More ...
New Alerts for Nextcloud, Microsoft Edge (Exploit), IBM, HPE, BD, and Linux. Nextcloud Global Site Selector password verification method allows a remote attacker to authenticate as another user. CVSSv3 score of 9.6More info. Microsoft Exploit Microsoft has updated Edge for the latest Chromium security updates. One has been exploited.More info...
New Alerts for Integration Objects, ABB, X.Org, Dell, Google Chrome (Exploit), BD, and Linux. Integration Objects OPC UA Server Toolkit contains an Improper Output Neutralization for Logs vulnerability. Successful exploitation of this vulnerability allows a remote attacker to add content to the log file. CVSSv3 score of 5.3No response from ve...
By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/