Skip to main content

CND News and Blog

New Vulnerabilities Thursday 23 May


New Alerts for Cisco, lighttpd, Progress, BD, and GitLab.

Cisco 

Cisco has published 5 new bulletins and 3 updated bulletins. Of the new bulletins, highest CVSSv3 score of 5.8
More info.

A vulnerability in the activation of an ACL on ASA and FTD software could allow a remote attacker to bypass the protection that is offered by a configured ACL on an affected device. CVSSv3 score of 5.8
More info.

Multiple Cisco products are affected by a vulnerability in the Snort IPS rule engine that could allow a remote attacker to bypass the configured rules on an affected system. CVSSv3 score of 5.8
More info.

A vulnerability in the file policy feature that is used to inspect encrypted archive files of FTD software could allow a remote attacker to bypass a configured file policy to block an encrypted archive file. CVSSv3 score of 5.8
More info.

A vulnerability in the Object Groups for ACLs feature of FMC software could allow a remote attacker to bypass configured access controls on managed devices. CVSSv3 score of 5.8
More info.

lighttpd 

A vulnerability exists in lighttpd whereby a remote attacker can craft an http request which could result in access to freed memory and allow the attacker to determine the state of memory, resulting in DoS or memory access.
More info.

Progress 

The Progress MOVEit Automation configuration export function uses a cryptographic method with insufficient bit length. CVSSv3 scoreof 6.1
More info.

BD 

BD has published security updates for third-party software used in Pyxis, Alaris, Care Coordination Engine, Identity Provider Manager, and Data Agent.
More info.

GitLab 

GitLab has published a security update that fixes several vulnerabilities. Highest CVSSv3 score of 8.0
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/