By michele654 on Thursday, 10 September 2020
Category: Vulnerabilities

New Vulnerabilities Thursday 10 September

New Alerts for IBM, Pepperl+Fuchs, ABB, Dell, and Linux.​ 

BLURtooth is a new Bluetooth attack.  Devices supporting both Bluetooth BR/EDR and LE using Cross-Transport Key Derivation (CTKD) for pairing are vulnerable to key overwrite, which enables an attacker to to gain additional access to profiles or services that are not restricted by reducing the encryption key strength or overwriting an authenticated key with an unauthenticated key.  

Mitsubishi Electric has patched a vulnerability in MC Works64 and MC Works32 initially reported in June.   

QNAP is just fixing some vulnerabilities initially publicized in January 2019, part of SOHOpelessy Broken 2.0.



Security Wizardry Cyber Threat Intelligence - The Radar Page

BLURtooth vulnerability lets attackers overwrite Bluetooth authentication keys | ZDNet

MITSUBISHI ELECTRIC Global website

Multiple Vulnerabilities in Helpdesk - Technical Advisory | QNAP

Leave Comments