Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 21 May


Atlassian has published Monthly Patches. New Alerts for TP-Link, AutomationDirect, Vertiv, BIND, Arista, and Linux.

TP-Link 

A stack-based buffer overflow vulnerability on the TP-Link Archer AX50 router allows a remote attacker to execute arbitrary code on the device over LAN and WAN networks. CVSSv4 score of 9.2
More info.

AutomationDirect 

AutomationDirect MB-Gateway contains a Missing Authentication in Critical Function vulnerability. CVSSv3 score of 10
Replacement of the device is the only option.
More info.

Vertiv 

Vertiv Liebert RDU101 and UNITY contains 2 vulnerabilities: Authentication Bypass Using an Alternate Path or Channel, Stack-based Buffer Overflow. Highest CVSSv4 score of 9.3
More info.

Atlassian 

Atlassian has published Monthly Patches for Bamboo Data Center and Server, Confluence Data Center and Server, Jira Data Center and Server, Fisheye/Crucible, and Jira Service Managment Data Center and Server. Highest CVSSv3 score of 7.5
More info.

BIND 

BIND has published a bulletin for a vulnerability that allows a remote attacker to use DNS message with invalid TSIG to cause an assertion failure. CVSSv3 score of 7.5
More info.

Arista 

Arista EOS UDP traffic may be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. |CVSSv3 score of 6.5
More info.

Linux 

SUSE has updated the kernel. More info.
OpenSUSE has updated the kernel. More info.
Red Hat has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/