By michele654 on Wednesday, 19 July 2023
Category: Vulnerabilities

New Vulnerabilities Wednesday 19 July


New Alerts for GeoVision, Weintek, Iagona, Rockwell Automation, Dell, and Google Chrome.

GeoVision 

GeoVision GV-ADR2701 cameras contain an Improper Authentication vulnerability. A remote attacker can edit the login response to access the web application. CVSSv3 score of 9.8
No patch, upgrade the physical camera.
More info.

Weintek 

Weintek Weincloud contains multiple vulnerabilities. Successful exploitation of these vulnerabilities could allow a remote attacker to utilize the JSON web token (JWT) to reset account passwords, use expired credentials, perform brute force attacks on credentials, or cause a DoS. Highest CVSSv3 score of 7.5
More info.

Iagona 

Iagona ScrutisWeb contains several vulnerabilities. Successful exploitation of these vulnerabilities could allow a remote attacker to upload and execute arbitrary files. Highest CVSSv3 score of 10.
More info.

Rockwell Automation 

An executable used in the ThinManager and ThinServer can be configured to enable an API feature in the HTTPS Server Settings, that can allow a remote attacker to exploit a path traversal vulnerability to leverage the privileges of the server's file system and read arbitrary files stored in it. CVSSv3 score of 7.5
More info.

Dell 

Dell PowerProtect Data Manager remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system. Dell rates this Critical.
More info.

Google 

Google has updated Chrome for Desktop to fix 20 security vulnerabilities.
More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments