New Alerts for SMA Technologies, IBM, Hikvision, Bosch, CODESYS, and Linux.
SMA Technologies
SMA Technologies OpCon UNIX agent adds the same SSH key on every installation and subsequent updates. An attacker with access to the private key can gain root access on affected systems.
More info.
IBM CICS TX Advanced could allow a remote attacker to execute arbitrary commands. CVSSv3 score of 9.8
More info. And here.
Security vulnerabilities in third-party software have been addressed in IBM Cognos Analytics. Highest CVSSv3 score of 9.8
More info.
The web module in some Hikvision Hybrid SAN/Cluster Storage products have insufficient input validation security vulnerabilities, allowing a remote attacker to execute restricted commands or cause a XSS attack. Highest CVSSv3 score of 7.5
More info.
Multiple vulnerabilities were found in the PRA-ES8P2S Ethernet-Switch including an Improper Input Validation, an Improper Privilege Management and an Execution with Unnecessary Privileges vulnerability. These vulnerabilities can give root access and/or administrator privilege to the switch from the network. Note the CVEs identified date back to 2006, although only the 3 most recent CVEs are patched. Highest CVSSv3 score of 9.8
More info.
CODESYS Gateway Server contains security vulnerabilities that allow an unauthenticated attacker to send crafted requests to cause the Server to allocate excessive memory or consume all available TCP client connections. Also, passwords are insufficiently checked during login. Highest CVSSv3 score of 9.8
More info.
CODESYS V2 products and CODESYS V3 products that communicate with V2 clients are affected by Unprotected Transport of Credentials and Insecure Default Initialization of Resource security vulnerabilities. The CODESYS V2 communication protocol transmits passwords unprotected. Also, password protection is not activated by default for the CODESYS Control runtime system V2. Highest CVSSv3 score of 9.8
More info.
SUSE has updated the kernel and fwupdate. More info.
Red Hat has updated the kernel. More info.
Oracle Linux has updated the kernel. More info.
Comments