By michele654 on Monday, 08 January 2024
Category: Vulnerabilities

New Vulnerabilities Monday 08 January


New Alerts for QNAP, Bosch, Microsoft, HPE, HP, NetApp, and Linux.

QNAP 

A vulnerability has been reported in Netatalk which affects QNAP OS. CVSSv3 score of 9.8
More info.

A prototype pollution vulnerability affects QNAP OS. The vulnerability allows a remote attacker to override existing attributes which causes the system to crash. CVSSv3 score of 7.5
More info.

Multiple vulnerabilities affect Video Station. Highest CVSSv3 score of 8.8
More info.

Bosch 

The Nexo cordless nutrunner running NEXO-OS contains multiple vulnerabilities that allow an attacker to manipulate files and databases, use hard-coded credentials to gain root access, perform a DoS, or achieve RCE. Highest CVSSv3 score of 8.8
More info.

Microsoft 

Microsoft has updated Edge to include the latest chromium fixes.
More info.

HPE 

Security vulnerabilities have been identified in HPE ProLiant RL300 Gen11 Servers. These vulnerabilities could be exploited to allow local unauthenticated disclosure of information, arbitrary code execution and remote access restriction bypass. Highest CVSSv3 score of 9.8
More info.

HP 

AMD security vulnerabilities affect HP platforms, which allow escalation of privilege, arbitrary code execution, denial of service, and/or information disclosure. Highest CVSSv3 score of 8.4
More info.

NetApp 

NetApp has published 5 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 6.5
Only one has patches.
More info.

Linux 

Mageia has updated the kernel firmware. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments