Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 12 April


Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Mozilla, SICK, Hikvision, and Linux.

Microsoft Exploit

Microsoft Monthly Patches are out with fixes for 114 vulnerabilities, 7 of which are Critical and 1 EoP vulnerability being exploited. Highest CVSSv3 score of 9.8
More info. And here. And here.

Adobe 

In their Monthly Patches, Adobe has published updates for Digital Editions, InCopy, Acrobat and Reader, Substance 3D Stager, Dimension, and 3D Designer. All are Critical, with remote and arbitrary code execution. Highest CVSSv3 score of 8.6
More info.

Fortinet 

Fortinet Monthly Patches include 21 new Bulletins, 1 rated Critical, 9 rated High, 10 rated Medium, and 1 rated Low. Highest CVSSv3 score of 9.3.
More info.

A missing authentication for critical function vulnerability in FortiPresence infrastructure server may allow a remote, attacker to access the Redis and MongoDB instances via crafted authentication requests. CVSSv3 score of 9.3
More info.

Mozilla 

Mozilla has published updates for Firefox, Firefox for Android, Focus for Android, Firefox ESR, and Thunderbird, all rated High.
More info.

SICK 

Several versions of the SICK Flexi Soft Gateways FX0-GENT, FX0-GMOD, FX0-GPNT and SICK Flexi Classic Gateway UE410 provide a Telnet interface for debugging, enabled by factory default with no password. If the password is set, a remote attacker could connect via Telnet. CVSSv3 score of 9.8
More info.

Hikvision 

Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain admin permission. A remote attacker can exploit the vulnerability by sending crafted messages to the affected devices. CVSSv3 score of 9.1
More info.

Linux 

Red Hat has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Thursday, 02 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/