Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 09 January


Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Palo Alto Networks, BD, Google ChromeOS, and Linux. Microsoft and Adobe Monthly Patches are expected this afternoon. 

Siemens 

Siemens has published their Monthly Patches, with 6 new bulletins and 11 updated bulletins. Of the new bulletins, highest CVSSv3 score of 10.
More info.

SIMATIC CN 4100 is vulnerable to authorization bypass through user-controlled key, use of default credentials and unauthenticated IP address change that could allow a remote attacker to login as root or cause a DoS. Highest CVSSv3 score of 9.8
More info.

MaxView Storage Manager shipped with affected SIMATIC IPCs contains a Redfish Server Vulnerability that could provide unauthorized access. CVSSv3 score of 10.
More info.

Schneider Electric 

Schneider Electric Monthly Patches include 1 new and 6 updated bulletins. The new bulletin has a CVSSv3 score of 7.8
More info.

SAP 

SAP Monthly Patches include 10 new Security Notes and 2 updated Notes. Of the new Notes, 2 are rated Hot News, 4 are rated High, 3 are rated Medium, and 1 rated Low. Highest CVSSv3 score of 9.1
More info.

Palo Alto Networks 

PAN-OS is vulnerable to the Terrapin MitM attack on SSH, if using the vulnerable algorithms. Highest CVSSv3 score of 6.8 for Terrapin.
More info.

BD 

BD has published security patches for Kiestra TLA/WCA and Kiestra ReadA.
More info.

Google 

Google has updated ChromeOS and ChromeOS Flex with several security fixes.
More info.

Linux 

Amazon Linux 1 has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Sunday, 05 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/