Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 20 June


New Alerts for Mitsubishi Electric, IBM, Zyxel, D-Link, Siren, ASUS, and Linux.

Mitsubishi Electric 

Several MELSEC IQ products have been added to a previous bulletin. A remote attacker can login to FTP server or Web server due to plaintext storage of passwords. CVSSv3 score of 7.5
More info.

IBM 

IBM Cloud Pak for Network Automation 2.4.7 fixes multiple security vulnerabilities. Highest CVSSv3 score of 9.8
More info.

IBM Spectrum Discover is vulnerable to multiple vulnerabilities. Highest CVSSv3 score of 9.8
More info.

IBM Copy Services Manager is vulnerable to remote attacks. Highest CVSSv3 score of 9.8
More info.

IBM Cloud Pak for Security includes components with multiple known vulnerabilities. Highest CVSSv3 score of 10
More info.

Zyxel 

Zyxel has released patches addressing a pre-authentication command injection vulnerability in some NAS versions. A Remote attacker could execute OS commands. CVSSv3 score of 9.8
More info.

D-Link 

DAP-2622 has a boundary error in the devices DDP service. This vulnerability can be exploited to cause a stack-based buffer overflow and subsequently execute arbitrary code on the device.
More info.

Siren 

Siren Investigate could allow a remote attacker to bypass security restrictions, caused by not invalidating the session keys after user logs out. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass access restrictions. CVSSv3 score of 9.1
More info.

ASUS 

ASUS has updated several router models to fix multiple security vulnerabilities. Highest CVSSv3 score of 9.8
More info. And here.

Linux 

SUSE has updated the kernel. More info.
Mageia has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Saturday, 04 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/