Skip to main content

CND News and Blog

New Vulnerabilities Thursday 13 July


Monthly Patches are out for Juniper Networks. New Alerts for Cisco, Apple (Exploit). Dell, SonicWall, Setelsa Security, NETGEAR, vm2, Wireshark, and Linux.

Cisco 

A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. CVSSv3 score of 9.1
More info.

Apple Exploit

Apple has released another Rapid Security Response for iOS, iPadOS, and macOS. This replaces the RSR released two days ago that was pulled. This is an update for an exploited vulnerability.
More info.

Juniper Networks

Juniper Monthly Patches are out with 17 bulletins, 2 rated Critical, 6 rated High, 8 rated Medium,
More info.

PHP software included with Junos OS J-Web has been updated to resolve multiple vulnerabilities. Highest CVSSv3 score of 9.8
More info.

Multiple vulnerabilities in third party software used in Juniper Networks Contrail Cloud have been resolved. Highest CVSSv3 score of 10
More info.

Multiple DoS vulnerabilities have been resolved in Juniper products. Highest CVSSv3 score of 7.5
More info. And here. And here. And here. And here.

Dell 

Dell PowerProtect Cyber Recovery remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. Dell rates this Critical.
More info.

SonicWall 

SonicWall GMS and Analytics products are affected by critical, high, and medium severity vulnerabilities. Highest CVSSv3 score of 9.8
More info.

Setelsa Security 

A relative path traversal vulnerability in Setelsa Security's ConacWin, the exploitation of which could allow an attacker to perform an arbitrary download of files from the system via the "Download file" parameter. CVSSv3 score of 7.5
More info.

NETGEAR 

NMS300 contains multiple security vulnerabilities. Highest CVSSv3 score of 9.8
More info.

vm2 

vm2 contains two RCE vulnerabilities. No patches are available yet. CVSSv3 score of 9.8
More info.

Wireshark 

Two DoS vulnerabilities have been fixed in Wireshark.
More info.

Linux 

Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Sunday, 12 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/