By michele654 on Friday, 15 November 2024
Category: Vulnerabilities

New Vulnerabilities Friday 15 November


New Alerts for Blackberry, Baxter, Microsoft Edge, Spring, NetApp, IBM, and Linux.

Blackberry 

Multiple vulnerabilities in SecuSUITE Server could allow a remote attacker to enroll an attacker-controlled device to the victim's account and telephone number or inject script commands or other executable content into the server that would run with root privilege. Highest CVSSv3 score of 7.3
More info.

Baxter 

Life2000 Ventilation System contains several vulnerabilities including hard-coded credentials, missing authentication, cleartext transmission of sensitive information, improper restriction of authentication attempts, and others. Highest CVSSv4 score of 10
Baxter plans an announcement for Q2 2025, until then watch your ventilators well.
More info. And here.

Microsoft 

Microsoft has updated Edge for the latest chromium updates and one Edge-specific vulnerability.
More info.

Spring 

Spring Framework has been updated to fix a DoS via Spring MVC controller method. CVSSv3 score of 5.4
More info.

NetApp 

NetApp has published 10 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
No patches yet.
More info.

IBM 

IBM has published several bulletins rated Critical, including updates for IBM CloudPak for AIOps, Tivoli Network Manager IP, CICS TX Advanced, DevOps Code ClearCase, Sterling Secure Proxy, and others.
More info.

Linux 

Ubuntu has updated the kernel. More info.
Amazon Linux 2023 has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details