Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 20 May


New Alerts for Spring, PowerDNS, VMware, Sungrow, Netgate, and IBM.

Spring 

Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass. CVSSv3 score of 9.1
More info.

PowerDNS 

A remote attacker can cause a DoS via a crafted TCP connection. CVSSv3 score of 7.5
More info.

VMware 

Multiple vulnerabilities in VMware Cloud Foundation were privately reported to VMware. Highest CVSSv3 score of 8.2
More info.

Sungrow 

Old versions of Sungrow Logger1000A/B products do not have a function to enforce default password changes for users, and users have not taken the initiative to modify the default password, allowing remote attackers to gain access to sensitive device information. CVSSv3 score of 3.7
More info.

Netgate 

Netgate has published 7 bulletins for pfSense.
More info.

IBM 

IBM has published Critical security bulletins for Integrated Analytics System, Maximo AI Service, and TSSC/IMC.
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/