By michele654 on Thursday, 16 November 2023
Category: Vulnerabilities

New Vulnerabilities Thursday 16 November


New Alerts for Red Lion, Wireshark, NetApp, IBM, TRENDnet, NetBSD, and Linux.

Red Lion 

Sixnet RTU contains two vulnerabilities, Authentication Bypass using an Alternative Path or Channel, and Exposed Dangerous Method or Function. Both have CVSSv3 score of 10.
Patches and mitigation instructions.
More info. And here.

Wireshark 

Wireshark has published two new bulletins identifying DoS vulnerabilities. CVSSv3 score of 6.5
More info. And here.

NetApp 

NetApp has published 14 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8
Only 2 have patches.
More info.

IBM 

Operations Dashboard is vulnerable to remote code execution due to Go. CVSSv3 score of 9.8
More info.

TRENDnet 

Several models of IP cameras have buffer overflow and command injection vulnerabilities that allows a remote attacker to take over the device and gain access to the OS.
More info.

NetBSD 

NetBSD has updated ftpd. A remote attacker may get directory listing, or cause buffer overflows.
More info.

Linux 

Red Hat has updated the kernel. More info.
Oracle Linux has updated the microcode. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details