Skip to main content

CND News and Blog

New Vulnerabilities Friday 07 April


New Alerts for Trellix, ICL (Exploit), Microsoft, IBM, and Open vSwitch.

Trellix 

ePolicy Orchestrator (ePO) contains a vulnerability in APR-util that allows an attacker to write beyond bounds of a buffer. CVSSv3 score of 9.8
More info.

ICL Exploit

On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 devices, remote attackers can overwrite, delete, or create files. This allows an attacker to execute critical file CRUD operations on the device that can potentially allow system access and impact availability. CVSSv3 score of 9.1
ICL is out of business, pull this out of your networks.
More info.

Microsoft 

Edge has updated for the latest chromium vulnerabilities.
More info.

IBM 

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data has been patched for vulnerabilities in third-party software.
More info. And here. And here. And here. And here. And here. And here.

Open vSwith

Multiple versions of Open vSwitch are vulnerable to crafted IP packets with ip proto set to 0 allowing a remote attacker to cause a DoS.
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/