Skip to main content

CND News and Blog

New Vulnerabilities Thursday 13 April


Monthly Patches for Juniper Networks are out. New Alerts for FANUC, NTP, IBM, Dell, Wireshark, and Linux. 

FANUC 

FANUC ROBOGUIDE-HandlingPRO contains a Path Traversal vulnerability that could allow a remote attacker to read and/or overwrite files on the system running the affected software. CVSSv3 score of 6.8
More info.

Juniper Networks

Juniper Monthly Patches include 26 bulletins, 2 rated Critical, 10 rated High, and 14 rated Medium. Highest CVSSv3 score of 9.8
More info.

Juniper Secure Analytics contains an Apache Commons Text vulnerability that allows RCE when applied to untrusted input due to insecure interpolation defaults. CVSSv3 score of 9.8
More info.

Junos OS has been updated to fix multiple vulnerabilities in expat. CVSSv3 score of 9.8
More info.

Junos OS and Junos OS Evolved contain a vulnerability that allows a malformed BGP flowspec update or specific genuine BGP packets to cause an RPD crash. CVSSv3 score of 7.5
More info. And here.

Junos OS MX Series contains a vulnerability that allows a specific traffic rate above the DDoS threshold to lead to an FPC crash. CVSSv3 score of 7.5
More info.

NTP 

Five vulnerabilities have been published for the latest version of ntp, collectively classified as Critical.
More info.

IBM 

IBM Security Verify Governance is vulnerable to a denial of service caused by multiple vulnerabilities that could allow a remote attacker to execute arbitrary code on the system. Highest CVSSv3 score of 9.8
More info. And here.

Netcool Operations Insight has addressed multiple security vulnerabilities. Highest CVSSv3 score of 9.8
More info.

Platform Navigator and Automation Assets in IBM Cloud Pak for Integration contain Webpack vulnerabilities that could allow a remote atatcker to bypass security restrictions. CVSSv3 score of 9.1
More info.

Vulnerabilities in cURL affect QLogic Virtual Fabric Extension Module for IBM BladeCenter. Highest CVSSv3 score of 9.8
More info.

Dell 

Dell EMC SRM and Dell EMC SMR remediation is available for multiple security vulnerabilities. Dell rates this Critical.
More info.

Wireshark 

Wireshark has published three security vulnerabilities rated Serious, all can lead to DoS.
More info.

Linux 

Oracle Linux has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/