Skip to main content

CND News and Blog

New Vulnerabilities Friday 25 April


New Alerts for Microsoft Edge, Johnson Controls, Nice, Planet Technology, Bosch, and Mitsubishi Electric.

Microsoft 

Microsoft has updated Edge with the latest chromium security fixes.
More info.

Johnson Controls 

Johnson Controls has updated Software House iSTAR Configuration Utility (ICU) tool to fix a vulnerability that allows a remote attacker to achieve buffer overflow. CVSSv4 score of 9.3
More info. And here.

Nice 

Nice Linear eMerge E3 contains an OS command injection vulnerability. CVSSv4 score of 9.3
Replace Controller boards if compromised.
More info. And here.

Planet Technology 

Planet Technology Network Products contain several vulnerabilities, including OS command injection, use of hard-coded credentials, and missing authentication for critical function. Highest CVSSv4 score of 9.3
More info.

Bosch 

Multiple ctrlX OS vulnerabilities exist in Device Admin and Solutions. Highest CVSSv3 score of 7.5
More info.

Mitsubishi Electric 

A DoS vulnerability exists in the Ethernet function of multiple FA products. CVSSv3 score of 5.9
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/