By michele654 on Wednesday, 11 January 2023
Category: Vulnerabilities

New Vulnerabilities Wednesday 11 January


New Alerts for Google Chrome, Moxa, Westermo, MAHO-PBX, NetApp, Western Digital, Black Box, and Linux.

Google 

Google has updated Chrome for Desktop to fix 17 security vulnerabilities.
More info.

Microsoft is aware. More info.

Moxa 

TN-4900 Series contains a Use of Hard-coded Credentials vulnerability that allows an attacker to gain privileges if an embedded credential is used. Note the CVE is from 2008.
More info.

Westermo 

Ibex Software 6 has a security vulnerability on units with SNMPv3 (v3usm) enabled that allows an attacker can get un-authorized access via SNMP. CVSSv3 score of 9.5
More info.

Mahoroba Kobo 

Multiple vulnerabilities exist in MAHO-PBX NetDevancer series. Highest CVSSv3 score of 9.8
More info.

NetApp 

NetApp has published 6 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 10
5 bulletins have patches.
More info.

Western Digital 

My Cloud OS 5 contains 4 security vulnerabilities that could be exploited by a remote attacker to achieve RCE.
More info.

Black Box 

Black Box KVM Switches and Extenders contain a Path Traversal vulnerability that allows an attacker to read sensitive data on the built-in web servers of the affected devices. CVSSv3 score of 7.5
More info.

Linux Patch

Ubuntu has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments