Skip to main content

CND News and Blog

New Vulnerabilities Friday 27 January


New Alerts for Rockwell Automation, Econolite, Microsoft PPTP, Microsoft Edge, IBM, and HCL Software.

Rockwell Automation 

Rockwell Automation is aware of multiple products that are affected by vulnerabilities in the GoAhead web server. Exploitation of these vulnerabilities could potentially have a high impact on the confidentiality, integrity and availability of the vulnerable devices. Highest CVSSv3 score of 9.8
Some products are patched, some not.
More info. And here.

Econolite 

Econolite EOS contains Improper Access Control and Use of Weak Hash vulnerabilities. Successful exploitation of these vulnerabilities could result in a remote attacker gaining full control over traffic control functions performed by Econolite hardware. Highest CVSSv3 score of 9.8
No response from Econolite.
More info.

Microsoft 

Microsoft has published a security advisory for Windows PPTP. A remote attacker could send a specially crafted connection request to a RAS server, which could lead to RCE on the RAS server machine. CVSSv3 score of 8.1
More info.

Microsoft has updated Edge with the latest chromium vulnerability fixes.
More info.

IBM 

There are multiple vulnerabilities in open source libraries used by IBM MobileFirst Platform Foundation. Highest CVSSv3 score of 10
More info.

HCL Software 

HCL BigFix WebUI is affected by security vulnerabilities in BigFix WebUI source code and open source components. Highest CVSSv3 score of 9.8
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 25 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/