By michele654 on Friday, 24 May 2024
Category: Vulnerabilities

New Vulnerabilities Friday 24 May


New Alerts for AutomationDirect, IBM, Google Chrome, D-Link, Mitel, and Linux.

AutomationDirect 

AutomationDirect Productivity PLCs contains multiple vulnerabilities. Highest CVSSv3 score of 9.3
More info.

IBM 

IBM Security Guardium is affected by multiple vulnerabilities. Highest CVSSv3 score of 9.8
More info.

IBM Spectrum Protect Plus Container backup and restore for OpenShift can be affected by vulnerabilities in third-party software. Highest CVSSv3 score of 9.8
More info.

IBM Storage Fusion is vulnerable to authorization bypass due to go-restful. CVSSv3 score of 9.3
More info.

Google 

Google has updated Chrome for Desktop to fix one security vulnerability.
More info.

D-Link 

D-Link Router Eagle Pro AI M18 AX1800 Smart Mesh Router includes legacy cipther protocols. Patches are expected next week.
More info.

Mitel 

An argument injection vulnerability in the MiCollab desktop client of Mitel MiCollab and MiVoice Business Solution Virtual Instance could allow a remote attacker to conduct an arbitrary argument injection attack due to insufficient parameter sanitization. CVSSv3 score of 8.8
More info.

Two vulnerabilities in the NuPoint Unified Messaging component of Mitel MiCollab could allow a remote attacker to conduct a SQL injection attack or execute arbitrary code. CVSSv3 score of 9.8
More info. And here.

Linux 

Red Hat has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details