Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 06 March


New Alerts for Apple (0-Day), Nice, Sophos, Moxa, Bosch, Google Chrome, HPE Aruba, and Linux.

Apple 0-Day

Apple has published updates for iOS fixing 4 vulnerabilities that allow privilege escalation, 2 of which have been exploited.
More info. And here.

Nice 

Linear eMerge E3-Series contains multiple vulnerabilities, including OS command injection, Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Insufficiently Protected Credentials, Use of Hard-coded Credentials, and Out-of-bounds Write, among others. Highest CVSSv3 score of 10.
More info.

Sophos 

UTM has been updated to fix a Tinyproxy vulnerability and several curl vulnerabilities, dating back to 2021. Highest CVSSv3 score of 7.5
More info.

Moxa

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service, resulting in DoS. CVSSv3 score of 8.2
More info.

Bosch 

BVMS contains a Device Adapter service that uses an OpenSSL library containing multiple vulnerabilities. These vulnerabilities could lead to command injection or denial of service. Highest CVSSv3 score of 9.8
More info.

Google 

Google has updated Chrome for Desktop to fix 3 security vulnerabilities, all rated High.
More info.

HPE

HPE ArubaOS and SD-WAN software contain vulnerabilities that allow a remote attacker to conduct DoS or disclose sensitive information, as well as other vulnerabilities requiring authentication. Highest CVSSv3 score of 7.2
More info. And here.

Linux 

SUSE has updated the linux firmware. More info.
Red Hat has updated the kernel. More info.
Amazon Linux 2023 has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Monday, 29 April 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/