Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 05 December


Monthly Patches are out for Google Android and Samsung. New Alerts for Pilz, Wago, CODESYS, Dell, Ivanti, and Linux.

Google 

Google Android patches are out with 34 vulnerabilities along with Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm patches. Of the Android patches, 4 are rated Critical and 30 are rated High.
More info.

Samsung 

Samsung Monthly Patches are out with Google Android and Samsung Semiconductor patches and at least 15 Samsung-specific SVEs.
More info.

Pilz 

The Builder and Viewer components of PASvisu are based on Electron which is affected by vulnerabilities in third-party software. The vulnerabilities may enable a remote attacker to gain full control over the system. CVSSv3 score of 8.8
More info.

Several Pilz products use libwebp, which may enable a remote attacker to gain full control over the system. CVSSv3 score of 8.8
More info.

Wago 

The Library WagoAppRTU, part of the Wago Telecontrol Configurator, is prone to improper input validation. By sending specifically crafted MMS packets a remote attacker can trigger a DoS. CVSSv3 score of 7.5
More info.

CODESYS 

Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime. CVSSv3 score of 9.8
More info. And here.

Dell 

Dell OS10 Networking Switches contain a DoS vulnerability when switches are configured with VLT and VRRP. A remote attacker can cause the network to be flooded leading to DoS. CVSSv3 score of 7.5
More info.

Dell PowerScale OneFS remediation is available for multiple security vulnerabilities. Highest listed CVSSv3 score of 8.8
More info.

Ivanti 

Several vulnerabilities exists in Ivanti Connect Secure that allow a remote attacker to achieve DoS. Highest CVSSv3 score of 7.5
More info.

Linux 

Amazon Linux 2 has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/