By michele654 on Wednesday, 05 August 2020
Category: Vulnerabilities

New Vulnerabilities Wednesday 5 August

New Alerts for IBM and Linux. 

GNU C has a remote code execution vulnerability, exploitable locally so doesn't make the Radar page, but worth taking a look.​

The Ripple20 vulnerabilities affect the Treck TCP/IP stack, but now CISA is reporting that "The Treck TCP/IP stack may be known by other names such as Kasago TCP/IP, ELMIC, Net+ OS, Quadnet, GHNET v2, Kwiknet, or AMX."

A hacker has published a list of plaintext usernames and passwords, along with IP addresses for more than 900 Pulse Secure VPN enterprise servers, which are still vulnerable to a CVE published a year ago.

Schneider Electric has begun rolling out some updates for their UPS products vulnerable to Ripple20.

Security Wizardry Cyber Threat Intelligence - The Radar Page

A Vulnerability in GNU C Library Could Allow for Remote Code Execution

Treck TCP/IP Stack (Update F) | CISA

Hacker leaks passwords for 900+ enterprise VPN servers | ZDNet

Security Notification – Treck TCP/IP Vulnerabilities (Ripple20) (2.1) | Schneider Electric

Leave Comments