Skip to main content

CND News and Blog

New Vulnerabilities Thursday 02 March


New Alerts for Cisco, Sophos, Mitsubishi Electric, BD, IBM, NetApp, StrongSwan, and Linux.

Cisco 

Cisco has published 5 new bulletins, 1 rated Critical and 4 rated Medium. Highest CVSSv3 score of 9.8
More info.

Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a DoS. Highest CVSSv3 score of 9.8
More info.

A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users who are connected through a load balancer. CVSSv3 score of 5.3
More info.

Sophos 

The Sophos Connect client has been updated to fix three security vulnerabilities, including a CSRF vulnerability that allows malicious websites to retrieve logs and technical support archives. Highest CVSSv3 score of 5.5
More info.

Mitsubishi Electric 

An information disclosure vulnerability due to Plaintext Storage of Password exists in MELSEC iQ-F Series. A remote attacker may be able to login to the FTP server or Web server by obtaining plaintext credentials stored in project files. CVSSv3 score of 7.5
More info.

BD 

BD has updated Microsoft and other third-party software in FACS Sample Prep Assistant, FACSCanto 10-color System, LSRFortessa, FACSCanto II, FACSAria, Accuri C6 Plus, FACSCelesta, FACSLyric, and FACSymphony A3/A5.
More info.

IBM 

IBM Cloud Pak for Network Automation has fixed multiple security vulnerabilities. Highest CVSSv3 score of 9.8
More info.

NetApp 

NetApp has published 13 new bulletins identifying vulnerabilities in third-party software included in their products. Five of the bulletins have patches. Highest CVSSv3 score of 9.8
More info.

StrongSwan 

A vulnerability related to certificate verification in TLS-based EAP methods was discovered in strongSwan that results in a denial of service but possibly even remote code execution.
More info.

Linux 

SUSE has updated the kernel. More info.
Oracle Linux has updated the kernel and systemd. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Tuesday, 16 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/