Skip to main content

CND News and Blog

New Vulnerabilities Thursday 29 February


New Alerts for Cisco, Juniper Networks, BD, Dell, Mitel, IBM, and Linux.

Happy Leap Day!

Cisco 

Cisco has published 5 new bulletins. Highest CVSSv3 score of 8.6
More info.

Vulnerabilities in the eBGP implementation and handling of MPLS traffic of Cisco NX-OS Software could allow a remote attacker to cause a DoS condition. CVSSv3 score of 8.6
More info. And here.

A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode could allow a remote attacker to cause a DoS on the Device Console UI. CVSSv3 score of 5.3
More info.

A vulnerability in the ACL programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow a remote attacker to send traffic that should be blocked. CVSSv3 score of 5.8
More info.

Juniper 

Multiple vulnerabilities resolved in Juniper Secure Analytics. Highest CVSSv3 score of 9.8
More info.

BD 

BD has provided a Google Chrome browser update for WebRTC, Skia, and WebP.
More info.

Dell 

Data Protection Advisor remediation is available for multiple vulnerabilities that could be exploited to compromise the affected system. Dell rates this Critical.
More info.

Dell VxFlex Ready Node and PowerFlex Custom Node remediation is available for multiple security vulnerabilities that could be exploited to compromise the affected system. Dell rates this High.
More info.

Mitel 

Two vulnerabilities in the legacy chat component of the MiContact Center Business could allow a remote attacker to conduct an information disclosure attack or a reflected XSS attack. Highest CVSSv3 score of 8.6
More info. And here.

IBM 

Vulnerabilities in AIX's OpenSSH could allow a remote attacker to launch a MitM attack and execute arbitrary commands. Highest CVSSv3 score of 9.8
More info.

Third party vulnerabilities have been patched in Engineering Requirements Management DOORS/DWA. Highest CVSSv3 score of 9.8
More info.

Multiple vulnerabilities were addressed in IBM Cloud Pak for Multicloud Management. Highest CVSSv3 score of 9.8
More info.

Multiple vulnerabilities were addressed in IBM Cloud Pak for AIOps. Highest CVSSv3 score of 10.
More info.

Multiple vulnerabilities in IBM WebSphere Liberty impact IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent. Highest CVSSv3 score of 9.8
More info.

Vulnerabilities exist in Semeru Java, Apache ActiveMQ, and Microsoft .Net MVC Framework for ASP.Net used by IBM Cognos Command Center. Highest CVSSv3 score of 9.4
More info.

Linux 

SUSE has updated the kernel. More info.
Red Hat has updated kpatch and the rt-kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Friday, 03 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/