Skip to main content

CND News and Blog

New Vulnerabilities Friday 01 September


New Alerts for ARDEREG, Moxa, Broadcom, Microsoft, IBM, Dell, NetApp, Ivanti, and Linux.

ARDEREG 

Sistemas SCADA contains a SQL Injection vulnerability that could allow a remote attacker to manipulate SQL query logic to extract sensitive information and perform unauthorized actions within the database. CVSSv3 score of 9.8
More info.

Moxa 

MXSecurity contains several security vulnerabilities that could allow a remote attacker to bypass authentication. Highest CVSSv3 score of 9.8
More info.

Broadcom 

The firmware download command on Brocade Fabric OS could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade. CVSSv3 score of 8.6
More info.

Microsoft 

Microsoft has updated Edge to include the latest updates for chromium, and 1 Edge-specific vulnerability.
More info.

IBM 

Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2023. Highest CVSSv3 score of 9.8
More info.

Dell 

Dell ECS remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. Dell rates this Critical.
More info.

NetApp 

NetApp has published 14 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
No patches yet.
More info.

Ivanti 

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. CVSSv3 score of 9.8
More info.

Linux 

Oracle Linux has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/