By michele654 on Sunday, 15 September 2024
Category: Vulnerabilities

New Vulnerabilities Sunday 15 September


New Alerts for curl, WebIQ, F5, and ABB.

curl 

When curl is built to use the GnuTLS library and told to use OCSP stapling to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine.
More info.

WebIQ 

The Windows version of WebIQ is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system. CVSSv3 score of 8.6
No patch yet.
More info.

F5 

Traffix SDC uses CPAN.pm which contains a vulnerability that may allow a remote attacker to inject into the network path and perform a MITM attack, causing confidentiality or integrity issues. CVSSv3 score of 7.4
More info.

ABB 

REF630, REG630, REM630 and RET630 equipment contains vulnerabilities that could result in a DoS. Highest CVSSv4 score of 8.2
More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details