Skip to main content

CND News and Blog

New Vulnerabilities Thursday 02 May


New Alerts for Dropbox Sign (Exploit), Cisco, SonicWall, Tinyproxy, IBM, and HashiCorp.

Dropbox Exploit

Dropbox has reported an incident in their Dropbox Sign product that exposed customer information as well as customers simply signing a document.
More info.

Cisco 

Multiple vulnerabilities in Cisco IP Phone firmware could allow a remote attacker to cause a DoS, gain unauthorized access, or view sensitive information on an affected system. CVSSv3 score of 7.5
More info.

SonicWall 

SonicWall GMS contains security vulnerabilities, including use of a hardcoded password. Highest CVSSv3 score of 7.5
More info.

Tinyproxy 

Tinyproxy contains security vulnerabilities that allows a remote atacker to achieve RCE. Highest CVSSv3 score of 9.8
No vendor response.
More info. And here. And here.

IBM 

Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation. Highest CVSSv3 score of 9.8
More info.

IBM Controller has addressed multiple vulnerabilities. Highest CVSSv3 score of 9.8
More info.

IBM QRadar SIEM on Azure Cloud deployed from Azure Marketplace is vulnerable to a remote code execution issue found within the Microsoft Open Management Infrastructure (OMI). CVSSv3 score of 9.8
More info.

HashiCorp 

Vault Enterprise leaks sensitive HTTP request headers in audit log when deployed with a Performance Standby node.
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Friday, 17 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/