Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 08 July


Monthly Patches are out for Samsung Android, MediaTek, Siemens, Schneider Electric, and SAP. Quarterly Patches are out for Splunk. New Alerts for Phoenix Contact, WAGO, and Linux.

Patches for Microsoft and Adobe are expected this afternoon.  Patches for Palo Alto and Juniper are expected tomorrow.

An item of note, there were no security patches for Google Android or Pixel this month.

MediaTek

MediaTek Monthly Patches include 16 fixed vulnerabilities, 7 rated High and 9 rated Medium.
More info.

Samsung

Samsung Android Monthly Patches include Samsung Semiconductor and 17 Samsung-specific SVEs.
More info.

Siemens

Monthly Patches from Siemens include 9 new bulletins and 17 updated bulletins. Of the new bulletins, highest CVSSv4 score of 9.3
More info.

Siemens SINEC NMS is affected by multiple vulnerabilities which could allow an attacker to elevate privilege and exceute arbitrary code. Highest CVSSv4 score of 9.3
More info.

Schneider Electric

Schneider Electric Monthly Patches include 4 new bulletins and 6 updated bulletins. Of the new bulletins, highest CVSSv4 score of 9.5
More info.

SAP

Monthly Patches for SAP include 27 new Security Notes and 4 updated. Highest CVSSv3 score of 9.9
More info.

Splunk

Splunk has published 12 security bulletins, 4 for Splunk and 8 for third-party software included in Splunk. Two are rated Critical, 1 rated High, 7 rated Medium, and 2 rated Low.
More info.

Phoenix Contact

Phoenix Contact has published 4 bulletins for vulnerabilities in CHARX SEC-3xxx charging controllers and PLCnext Firmware. Highest CVSSv3 score of 9.8
More info.

WAGO

WAGO Device Sphere has been updated to fix a vulnerability that installs identical certificates across all systems instead of unique ones, which are intended for JWT Token encryption and signing. A remote attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices. CVSSv3 score of 10.
More info.

Linux

SUSE has updated the kernel. More info.
OpenSUSE has updated the kernel. More info.
Red Hat has updated the kernel-rt. More info.
Oracle Linux has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/