Skip to main content

CND News and Blog

New Vulnerabilities Friday 08 July


New Alerts for Bentley Nevada, Node.js, Santesoft, Rockwell Automation, F5, NetApp, and Linux.

Bentley Nevada 

Bentley Nevada 3701/4X and 60M100 (3701/60) Condition Monitoring System contain vulnerabilities identified as OT:ICEFALL, including Use of Hard-coded Credentials and Missing Authentication. Highest CVSSv3 score of 9.1
More info.

Node.js 

A security release is available that fixes 2 High and 5 Medium vulnerabilities. Highest CVSSv3 score of 9.6
More info.

Santesoft 

Sante PACS Server contains a vulnerability that allows remote attackers to bypass authentication on affected installations of Sante PACS Server. The specific flaw exists within the processing of calls to the login endpoint. When parsing the username element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to bypass authentication on the system. CVSSv3 score of 9.8
More info.

Rockwell Automation 

Rockwell Automation was made aware that the X-Frame-Options header is not configured in the HTTP response and allows potential clickjacking attacks. Exploitation of this vulnerability could potentially allow a malicious user to trick a legitimate user into using an untrusted website. If exploited, this vulnerability could lead to a loss of sensitive information, such as authentication credentials. CVSSv3 score of 6.5
More info. And here.

F5 

Traffix SDC contains a vulnerability in Apache Tomcat that allows a remote attacker to copromise the affected system. CVSSv3 score of 8.6
More info.

NetApp 

NetApp has published 10 new bulletins identifying vulnerabilities in third-party software that is included in their products. Four of them include patches.
More info.

Linux 

SUSE has updated rsyslog, crash, fwupd, and others. More info.
OpenSUSE has updated fwupd and others. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Tuesday, 16 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/