Skip to main content

CND News and Blog

New Vulnerabilities Friday 27 October


New Alerts for Sielco (Exploit), Dingtian (Exploit), F5, BD, and IBM.

Sielco Exploit

Sielco PolyEco1000 contains several vulnerabilities, including Session Fixation, Improper Restriction of Excessive Authentication Attempts, Improper Access Control. Highest CVSSv3 score of 9.8
No response from vendor, exploit exists.
More info.

Analog FM Transmitters and Radio Link contain several ulnerabilities, including Improper Access Control, Cross-Site Request Forgery, Privilege Defined with Unsafe Actions. Highest CVSSv3 score of 9.8
No response from vendor, exploit exists.
More info.

Dingtian Exploit

DT-R002 contains a vulnerability that allows Authentication Bypass by Capture-Replay. CVSSv3 score of 5.9
No response from vendor, exploit exists.
More info.

F5 

BIG-IP Configuration utility contains a RCE vulnerability, that allows a remote attacker with access to the control plane to execute arbitrary system commands. CVSSv3 score of 9.8
More info.

BD 

BD has published updates for Alaris PCU and Alaris System with Guardrails Suite MX.
More info.

IBM 

IBM UrbanCode has been updated to address multiple vulnerabilities in third-party software. Highest CVSSv3 score of 9.8
More info. And here.

IBM QRadar SIEM has been updated to address multiple vulnerabilities in third-party software. Of note is the Apache Log4j vulnerability from 2019. Highest CVSSv3 score of 9.8
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Sunday, 28 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/