Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 06 September


Monthly Patches are out for Fortinet. New Alerts for Hitachi Energy, Hitachi, Zyxel, and WithSecure. 

I expected Qualcomm, Samsung, and Android patches today. They may come this afternoon, or not until next week because of the Monday holiday.


Hitachi Energy 

Hitachi Energy AFS660/AFS665 series contains a security vulnerability that could allow an attacker to fully compromise the target device. CVSSv3 score of 9.8
More info.

Hitachi Energy MicroSCADA Pro/X SYS600 products contain security vulnerabilties in the product as well as open source software included with the product. Highest CVSSv3 score of 8.5
More info. And here.

Hitachi 

Cosminexus XML Processor contains a vulnerability in Apache Xerces Java. CVSSv3 score of 6.5
More info.

Fortinet 

Fortinet Monthly Patches are out, with 12 new bulletins. One rated High, 9 rated Medium, and 1 rated Low.
More info.

An improper verification of source of a communication channel vulnerability in FortiOS may allow a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim. CVSSv3 score of 6.6
More info.

Zyxel 

A format string vulnerability was found in a specific binary of Zyxel NAS products that could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet. CVSSv3 score of 9.8
Only supported products are patched.
More info.

WithSecure 

A DoS vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing the scanning request. The exploit can be triggered remotely by an attacker.
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Tuesday, 23 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/