Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 26 August


New Alerts for Citrix, Welotec, Hitachi Energy, Delta, HPE, and TRUMPF.

Citrix

Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway. Highest CVSSv4 score of 9.2
More info.

Welotec

The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. A remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key. CVSSv3 score of 9.8
More info.

Hitachi Energy

Hitachi Energy is aware of a remote code execution vulnerability that affects the Oracle WebLogic component in Service Suite allowing a remote attacker to cause confidentiality, integrity and availability impacts. CVSSv3 score of 9.8
More info.

Multiple reported vulnerabilities affect Asset Suite that can potentially impact on confidentiality, integrity and availability of the product. Highest CVSSv3 score of 7.8
More info.

Delta

Delta's COMMGR contains Stack-based Buffer Overflow and Code Injection Vulnerabilities. Highest CVSSv3 score of 8.6
More info.

HPE

Security vulnerabilities have been identified in HP-UX PAM RADIUS that may cause Denial of Service, Cross-Site Request Forgery and Buffer Overflow. Highest CVSSv3 score of 9.0
More info.

TRUMPF

The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible to change the encryption settings. CVSSv3 score of 7.5
More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/