Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 24 September


New Alerts for Google Chrome, SolarWinds, WAGO, AutomationDirect, Dell, IBM, and Linux.

Google

Google has updated Chrome for Desktop to fix 3 security vulnerabilities.
More info.

Microsoft is aware. More info.

SolarWinds

SolarWinds has published a hotfix for Web Help Desk to fix an unauthenticated AjaxProxy deserialization remote code execution vulnerability. CVSSv3 score of 9.8
More info. And here.

WAGO

Due to a missing authentication check, the WAGO Solution Builder and the WAGO Device Sphere are vulnerable to a potential information exposure. Highest CVSSv3 score of 9.8
More info.

AutomationDirect

AutomationDirect CLICK PLUS contains several vulnerabilities that disclose sensitive information, modify device settings, escalate privileges, or cause a denial-of-service condition on the affected device. Highest CVSSv4 score of 8.7
More info.

Dell

Dell has published a Critical bulletin for Data Protection Central.
More info.

IBM

IBM has published Critical bulletins for Netezza Replication Services, App Connect Enterprise, Maximo Application Suite, Cloud Pak for Automation, watsonx BI, Tivoli Netcool Configuration Manager.
More info.

Linux

SUSE has updated the kernel. More info.
OpenSUSE has updated the kernel. More info.
Oracle Linux has updated the kernel. More info.
Ubuntu has updated the kernel. More info.
AlmaLinux has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/