By michele654 on Thursday, 12 September 2024
Category: Vulnerabilities

New Vulnerabilities Thursday 12 September


Monthly Patches are out for Palo Alto Networks. New Alerts for Cisco, iniNet, Microsoft Edge, HPE, Zyxel, HPE, Tenable, Dell, and Linux.

Cisco 

Cisco has published 8 new bulletins, 6 rated High and 2 rated Medium. Highest CVSSv3 score of 8.8
More info.

A vulnerability in the Mtrace2 feature of Cisco IOS XR Software could allow a remote attacker to exhaust the UDP packet memory of an affected device, resulting in a DoS. CVSSv3 score of 8.6
More info.

A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow a remote attacker to cause a DoS on XML TCP listen port 38751. CVSSv3 score of 5.3
More info.

Palo Alto Networks 

Palo Alto Networks Monthly Patches include 7 bulletins, 2 rated High and 5 rated Medium. Highest CVSSv4 score of 8.6
More info.

Prisma Access Browser has incorporated the latest upstream Chromium security fixes. Highest CVSSv3 score of 8.8
More info.

A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. CVSSv4 score of 6.
More info.

iniNet 

SpiderControl SCADA Web Server contains an Unrestricted Upload of File with Dangerous Type vulnerability. CVSSv4 score of 8.7.
More info.

Microsoft 

Microsoft has updated Edge with the latest chromium fixes and 1 Edge specific vulnerability.
Note: This is currently not reflected in the Edge Release Note page.
More info. And here.

HPE 

HPE NonStop Vrtual Tape Repository (VTR) contains several vulnerabilities. Highest CVSSv3 score of 9.8
More info.

Zyxel 

Zyxel has released hotfixes addressing command injection vulnerability in two NAS products that have reached EoS. A remote attacker could execute some OS commands by sending a crafted HTTP POST request. CVSSv3 score of 9.8
More info.

Tenable 

Tenable has updated Nessus to fix vulnerabilities in third-party software. Highest CVSSv3 score of 9.8
More info.

Dell 

Security update has been published for Dell Data Protection Central for third-party software vulnerabilities.. Dell rates this Critical.
More info.

Dell ThinOS remediation is available for multiple vulnerabilities in third-party software. Dell rates this Critical.
More info.

Dell Avamar remediation is available for Switch OS 10.5.x-Gen5A vulnerabilities. Dell rates this High.
More info.

Dell PowerScale InsightIQ remediation is available for multiple security vulnerabilities in third-party software. Dell rates this High.
More info.

Linux 

SUSE has updated the kernel. More info.
OpenSUSE has updated the kernel. More info.
Oracle Linux has updated the kernel. More info.
Ubuntu has updated the kernel. More info.
Mageia has updated the microcode. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details