By michele654 on Tuesday, 18 March 2025
Category: Vulnerabilities

New Vulnerabilities Tuesday 18 March


New Alerts for Ricoh, MB Connect, IBM, Helmholz, and CODESYS.

Ricoh 

Ricoh MFP and Printers contain vulnerabilities in the PostScript interpreter and embeded webserver that could result in RCE. Highest CVSSv3 score of 9.1
More info.

MB Connect 

The data24 service that is bundled with every installation of mbCONNECT24/mymbCONNECT24 has two vulnerabilities in core components that can lead to a complete loss of confidentiality, integrity and availability. Highest CVSSv3 score of 9.1
More info.

IBM 

IBM has published a Critical bulletin for Rapid Infrastructure Automation.
More info.

Helmholz 

The data24 service that is bundled with every installation of myREX24/myREX24.virtual has two vulnerabilities in core components that can lead to a complete loss of confidentiality, integrity and availability. Highest CVSSv3 score of 9.1
More info.

CODESYS 

Due to an insecure standard configuration of the CODESYS Gateway, it is accessible remotely by default. CVSSv3 score of 5.3
More info.

The OPC UA contains an optional security policy that is vulnerable against attacks on the private key, resulting in loss of confidentiality or authentication bypass. The affected policy may be enabled by a customer configuration. CVSSv3 score of 7.5
More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details