Skip to main content

CND News and Blog

New Vulnerabilities Thursday 13 March


Monthly Patches are out for Cisco and Palo Alto Networks. New Alerts for Microsoft Edge, Xerox, ABB, Lenovo, and Linux.

Cisco 

Cisco has published 11 bulletins, 8 rated High and 3 rated Medium. Highest CVSSv3 score of 8.6
More info.

Vulnerabilities in the IPv4 ACL feature, QoS policy feature, and Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000, ASR 9902 Compact, and ASR 9903 Compact could allow a remote attacker to cause a line card to reset, resulting in a DoS. CVSSv3 score of 8.6
More info. And here.

A vulnerability in the IKEv2 function of Cisco IOS XR Software could allow a remote attacker to prevent an affected device from processing any control plane UDP packets. CVSSv3 score of 7.5
More info.

Palo Alto Networks 

Palo Alto Networks has published 6 bulletins, 1 rated High, 4 rated Medium, and 1 rated Low. Highest CVSSv3 score of 7.6
More info.

Microsoft 

Microsoft has updated Edge with the latest chromium updates.
More info.

Xerox 

Xerox has published Security updates for FreeFlow Print Server.
More info.

ABB 

RMC-100 and RMC-100 LITE has been updated to fix a vulnerability that allows a remote attacker to send a specially crafted message to the web UI node, causing a DoS. CVSSv3 score of 7.5
More info.

Lenovo 

Lenovo has published a bulletin for BIOS from vendors that could allow a remote attacker to cause a DoS.
More info.

An authentication bypass vulnerability in the MegaRAC Redfish Host Interface affects Lenovo products. CVSSv3 score of 9.8
More info.

Linux 

SUSE has updated the kernel. More info.
OpenSUSE has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/