By michele654 on Tuesday, 20 February 2024
Category: Vulnerabilities

New Vulnerabilities Tuesday 20 February


New Alerts for PostgreSQL (pgjdbc), Mitsubishi Electric, ConnectWise, HPE, Zyxel, and Linux.

PostgreSQL 

pgjdbc, the PostgreSQL JDBC driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. CVSSv3 score of 10.
More info.

Mitsubishi Electric 

A RCE vulnerability due to Microsoft Message Queuing service on Microsoft Windows exists in Electrical discharge machines. A remote attacker can execute malicious code on the product by sending specially crafted packets. CVSSv3 score of 9.8
More info.

ConnectWise 

ConnectWise ScreenConnect has been updated to fix 2 vulnerabilities. Highest CVSSv3 score of 10.
More info.

HPE 

A security vulnerability in Apache Tomcat impacts HPE IceWall products. A remote attacker could exploit the vulnerability to disclose sensitive information. CVSSv3 score of 5.3
More info.

Zyxel 

Zyxel has released patches addressing multiple vulnerabilities in some firewall and access point (AP) versions. One of the vulnerabilities can allow a remote attackerm to achieve RCE. Highest CVSSv3 score of 8.1
More info.

Linux 

Red Hat has updated the kernel and kpatch. More info.
Amazon Linux has updated the kernel. More info.
Amazon Linux 2 has updated the kernel. More info.
Amazon Linux 2023 has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments