Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 12 September


Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Microsoft Edge (0-Day), Apple (exploit), Zoom, and Linux.

Monthly Patches for Microsoft and Adobe are expected this afternoon.

Siemens 

Siemens Monthly Patches contain 7 new bulletins and 14 updated bulletins. Of the new bulletins, highest CVSSv3 score of 9.0
More info.

The ANSI C OPC UA SDK contained in SIMATIC products contains an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. A remote attacker can create a DoS by sending a specially crafted certificate. CVSSv3 score of 7.5
More info.

Siemens includes CodeMeter Runtime in some of their products, which has a vulnerability that could allow a remote attacker to achieve RCE. CVSSv3 score of 9.0
More info.

Schneider Electric 

Schneider Electric Monthly Patches contains just 1 bulletin, CVSSv3 score of 7.8
More info.

SAP 

SAP has published Monthly Patches with 13 new bulletins and 5 updated bulletins. Of the new bulletins, 2 are rated Hot News, 2 High, 7 Medium, and 2 Low. Highest CVSSv3 score of 9.9
More info.

Microsoft 0-Day

Microsoft is aware of exploits for Edge in the wild, and is working on a patch.
More info.

Apple Exploit

Apple has published updates for older versions of iOS, iPadOS, and macOS that patches the recently discussed public exploits. Newer versions are already patched.
More info.

Zoom 

Zoom Desktop Client for Linux contains an Improper Input Validation vulnerability that allows a remote attacker to cause a DoS.
More info.

Linux 

Red Hat has updated the kernel-rt and firmware. More info.
Oracle Linux has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Saturday, 18 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/