Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 14 March


Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Microsoft Edge, Phoenix Contact, and Omron.    

Monthly Patches for Microsoft and Adobe should be out this afternoon.    

Palo Alto Networks Monthly Patches are due tomorrow. 

Siemens 

Siemens Monthly Patches are out, with 7 new bulletins and 23 updated bulletins. Of the new bulletins, highest CVSSv3 score of 9.8
More info.

Multiple third-party component vulnerabilities were reported for the Busybox applet, the Linux Kernel, OpenSSL, OpenVPN and various other components used by the RUGGEDCOM and SCALANCE products. Highest CVSSv3 score of 9.8
More info.

The Mendix SAML module insufficiently verifies the SAML assertions. This could allow a remote attacker to bypass authentication and get access to the application. CVSSv3 score of 9.1
More info.

The RADIUS client implementation of the VxWorks platform in SIPROTEC 5 devices contains a DoS that could be triggered when a specially crafted packet is sent by a RADIUS server. CVSSv3 score of 7.5
More info.

Multiple vulnerabilities affecting various third-party components of SCALANCE W-700 IEEE 802.11ax devices could allow a remote attacker to cause a DoS, disclose sensitive data or violate the system integrity. Highest CVSSv3 score of 8.1
More info.

Schneider Electric 

Schneider Electric Monthly Patches include 3 new bulletins and 15 updated bulletins. Of the new bulletins, highest CVSSv3 score of 9.8
More info.

PowerLogic HDPM6000 products contain an improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in DoS or RCE. CVSSv3 score of 9.8
More info.

Multiple vulnerabilities exist in Data Server, Dashboard and Custom Reports modules for the IGSS. Highest CVSSv3 score of 8.8
More info.

SAP 

SAP Patch Day is here, with 19 new Security Notes. 5 are rated Hot News, 4 rated High, and 10 rated Medium. Highest CVSSv3 score of 9.9
More info.

Phoenix Contact 

ENERGY AXC PU uses CODESYS Control V3 runtime system, which contains several vulnerabilities. Highest CVSSv3 score of 8.1
More info.

Microsoft 

Microsoft has updated Edge with the latest chromium security fixes.
More info.

Monthly Patches are expected out later today.

Omron 

Improper Access Control vulnerabilities exist in the CS/CJ/CP-series Programmable Controllers. A remote attacker can use these vulnerabilities to bypass protection system of the user memory, disable a password, overwrite a new password, and overwrite a code for executing the user program (object code) or a function block. CVSSv3 score of 9.1
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Saturday, 20 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/