Skip to main content

CND News and Blog

New Vulnerabilities Friday 18 October


New Alerts for Microsoft Edge, Synology, Kieback&Peter, Spring, Belden, OPC Foundation, Hikvision, Moxa, and NetApp.

Microsoft 

Microsoft has updated Edge to include the latest chromium fixes and 9 Edge-specific vulnerabilities.
More info.

Synology 

Synology Camera BC500, TC500, and CC400W contain vulnerabilities that allow remote attackers to execute arbitrary code, bypass security constraints and conduct DoS attacks. Synology rates this Critical.
More info.

A vulnerability allows remote attackers to execute arbitrary code via a susceptible version of Synology BeeStation Manager. Synology rates this Critical.
More info.

Kieback&Peter 

DDC4000 Series contains Path Traversal, Insufficiently Protected Credentials, and Use of Weak Credentials vulnerabilities, that allows a remote attacker to gain full administrator rights on the system. Highest CVSSv4 score of 9.3
This product line is considered EOL.
More info.

Spring 

Spring has been updated to fix 2 vulnerabilities. Highest CVSSv3 score of 7.5
More info.

Belden 

A vulnerability in HiLCOS web interface allows a remote attacker to trigger a DoS. CVSSv3 score of 7.0
More info.

OPC Foundation 

A vulnerability in the OPC UA .NET Standard Stack allows a remote attacker to trigger a gradual degradation in performance. CVSSv3 score of 5.3
More info.

Hikvision 

Several vulnerabilities have been fixed in HikCentral Master Lite and Professional. Highest CVSSv3 score of 7.2
More info.

Moxa 

MXsecurity Series is affected by two vulnerabilities, included hardcoded credentials and exposed functions. CVSSv3 score of 5.3
More info.

NetApp 

NetApp has published 10 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
No patches yet.
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/