Skip to main content

CND News and Blog

New Vulnerabilities Thursday 08 February


New Alerts for Cisco, ClamAV, SonicWall, IBM, NetApp, Django, and Linux.

Cisco 

Multiple vulnerabilities in the Cisco Expressway Series could allow a remote attacker to conduct CSRF attacks, which could allow the attacker to perform arbitrary actions on an affected device. CVSSv3 score of 9.6
More info.

Secure Endpoint products are affected by a vulnerability in the OLE2 file format parser of ClamAV that could allow a remote attacker to cause a DoS on an affected device. CVSSv3 score of 7.5
More info.

ClamAV 

Two security vulnerabilities have been patched in ClamAV that allowed DoS and command injection.
More info.

SonicWall 

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which could allow a remote attacker to bypass authentication. CVSSv3 score of 8.6
More info.

IBM 

IBM Sterling Control Center is vulnerable to DoS due to Spring Boot and RCE due to Spring Framework. Highest CVSSv3 score of 9.8
More info.

A vulnerability in Apache Derby affects IBM Cloud Pak System. CVSSv3 score of 9.1
More info.

Vulnerabilities contained within OpenVPN, OpenSSL, and Elipse Jetty and Netty were addressed in MaaS360 Cloud Extender Agent and VPN Modules, and MaaS360 Mobile Enterprise Gateway (MEG). Highest CVSSv3 score of 9.8
More info.

A vulnerability with the Linux kernel affects IBM Cloud Object Storage Systems. CVSSv3 score of 9.8
More info.

NetApp 

NetApp has published 10 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
Only one patch is available.
More info.

Django 

Django has been updated to fix a vulnerability in the intcomma template filter that could result in a DoS.
More info.

Linux 

Red Hat has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/