Skip to main content

CND News and Blog

New Vulnerabilities Thursday 12 January


Quarterly Patches are out for Juniper Networks. New Alerts for Cisco, WAGO, IBM, Zyxel, and Linux.

Cisco 

Cisco has published 11 new bulletins, 1 Critical, 3 High, and the rest Medium. Highest CVSSv3 score of 9.0
More info.

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow a remote attacker to bypass authentication or execute arbitrary commands on the underlying operating system of an affected device. Highest CVSSv3 score of 9.0
More info.

A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. CVSSv3 score of 8.6
More info.

A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. CVSSv3 score of 8.6
More info.

WAGO 

A vulnerability in the web-based management of WAGOs PLC could allow an unauthenticated remote attacker to retrieve a backup file, that may contain sensitive information. CVSSv3 score of 4.3
More info.

IBM 

IBM App Connect Enterprise Certified Container DesignerAuthoring and IntegrationServer operands may be vulnerable to arbitrary code execution. CVSSv3 of 9.8
More info.

Multiple vulnerabilities in Java and Node.js packages affect IBM Voice Gateway. Highest CVSSv3 score of 10
More info.

Zyxel 

Zyxel has released patches for some switches affected by a DoS vulnerability. An improper check for unusual or exceptional conditions in the HTTP request processing function of some Zyxel switch versions could allow an attacker to corrupt the contents of the memory and result in a DoS condition on an affected device.
More info.

Juniper Networks 

Juniper Networks Quarterly Patches are out, with 32 bulletins, 3 rated Critical, 19 rated High, and 10 rated Medium. Highest CVSSv3 score of 9.8
More info.

Multiple vulnerabilities exist in third party software used in Juniper Networks Contrail Cloud and Junos Space. Highest CVSSv3 score of 9.8
More info. And here.

Multiple vulnerabilities have been resolved in Juniper Networks Contrail Service Orchestration (CSO), by updating third party software included with CSO or by fixing vulnerabilities found during external security research. Highest CVSSv3 score of 9.8
More info.

Linux 

Red Hat has updated the kernel-rt and kpatch. More info.
Oracle Linux has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Friday, 26 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/