Skip to main content

CND News and Blog

New Vulnerabilities Thursday 20 April


New Alerts for Cisco, PaperCut (Exploit), TIBCO, Microsoft Edge (Exploit), NetApp, and HCL Software. 


Cisco 

Cisco has published 6 new bulletins and 2 updated bulletins. Of the new bulletins, 2 are rated Critical, 2 rated High, and 2 rated Medium. Highest CVSSv3 score of 9.9
More info.

A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote attacker to access the web interface with administrative privileges. CVSSv3 score of 9.1
More info.

A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources, causing a DoS condition. CVSSv3 score of 8.6
More info.

PaperCut Exploit

PaperCut MF/NG has two vulnerabilities that are currently being exploited, one being an unauthenticated RCE vulnerability. Highest CVSSv3 score of 9.8
More info. And here.

TIBCO 

TIBCO Spotfire Splus Server contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. CVSSv3 score of 9.8
More info.

Microsoft Exploit

Microsoft has updated Edge to include the fix for the exploited CVE fixed in chromium yesterday.
More info.

NetApp 

NetApp has published 12 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8, 6 have patches.
More info.

HCL Software 

HCL Connections includes IBM Security Directory Integrator, which contains several vulnerabilities. Highest CVSSv3 score of 9.8
More info.

HCL Commerce includes IBM Db2, which contains several vulnerabilities. Highest CVSSv3 score of 9.8
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/