Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 20 February


New Alerts for PostgreSQL (pgjdbc), Mitsubishi Electric, ConnectWise, HPE, Zyxel, and Linux.

PostgreSQL 

pgjdbc, the PostgreSQL JDBC driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. CVSSv3 score of 10.
More info.

Mitsubishi Electric 

A RCE vulnerability due to Microsoft Message Queuing service on Microsoft Windows exists in Electrical discharge machines. A remote attacker can execute malicious code on the product by sending specially crafted packets. CVSSv3 score of 9.8
More info.

ConnectWise 

ConnectWise ScreenConnect has been updated to fix 2 vulnerabilities. Highest CVSSv3 score of 10.
More info.

HPE 

A security vulnerability in Apache Tomcat impacts HPE IceWall products. A remote attacker could exploit the vulnerability to disclose sensitive information. CVSSv3 score of 5.3
More info.

Zyxel 

Zyxel has released patches addressing multiple vulnerabilities in some firewall and access point (AP) versions. One of the vulnerabilities can allow a remote attackerm to achieve RCE. Highest CVSSv3 score of 8.1
More info.

Linux 

Red Hat has updated the kernel and kpatch. More info.
Amazon Linux has updated the kernel. More info.
Amazon Linux 2 has updated the kernel. More info.
Amazon Linux 2023 has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/