Skip to main content

CND News and Blog

New Vulnerabilities Thursday 29 September


New Alerts for Cisco, Mitsubishi Electric, Brocade, and Linux.

Cisco 

Cisco has published 21 new bulletins, 13 rated High and the rest Medium. Highest CVSSv3 score of 8.6
More info.

A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points could allow an unauthenticated, remote attacker to cause a DoS condition. CVSSv3 score of 8.6
More info.

A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst 3850, and Catalyst 9000 Family Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. CVSSv3 score of 8.6
More info.

A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a DoS condition. CVSSv3 score of 8.6
More info.

A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a DoS condition. CVSSv3 score of 8.6
More info.

A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. CVSSv3 score of 8.6
More info.

Mitsubishi Electric 

Information disclosure vulnerability due to the use of Basic Authentication for HTTP connections exists in multiple consumer electronics products. CVSSv3 score of 5.9
More info.

A DoS vulnerability due to use of freed memory and a client-side script injection vulnerability due to cross-site scripting exist in multiple consumer electronics products. Highest CVSSv3 score of 6.8
More info.

Brocade 

Brocade Active Support Connectivity Gateway and Brocade Fabric OS contain a DoS vulnerability from OpenSSL. CVSSv3 score of 7.5
More info.

Linux 

SUSE has updated the kernel. More info.
Red Hat has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Wednesday, 24 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/