Skip to main content

CND News and Blog

New Vulnerabilities Thursday 20 July

New Alerts for OpenSSH (Exploit), Adobe (Exploit), Atlassian, Ivanti, and Linux. OpenSSH Exploit The PKCS#11 support ssh-agent could be abused to achieve remote code execution via a forwarded agent socket. Exploitation requires specific libraries on the victim system and the agent forwarded to an attacker-controlled system.More info. Adobe Exploit ...

0
  447 Hits
  0 Comments

New Vulnerabilities Wednesday 19 July

New Alerts for GeoVision, Weintek, Iagona, Rockwell Automation, Dell, and Google Chrome. GeoVision  GeoVision GV-ADR2701 cameras contain an Improper Authentication vulnerability. A remote attacker can edit the login response to access the web application. CVSSv3 score of 9.8No patch, upgrade the physical camera.More info. Weintek  Weintek...

0
  529 Hits
  0 Comments

New Vulnerabilities Tuesday 18 July

Quarterly Patches are expected for Oracle this afternoon. New Alerts for Rockwell Automation, IBM, NetApp, Veritas, Citrix (Exploit), and Linux. Rockwell Automation  The Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits opera...

0
  543 Hits
  0 Comments

New Vulnerabilities Monday 17 July

New Alerts for Adobe (Exploit), Secomea, Bitdefender, and Linux.         Tomorrow is Oracle Quarterly Patch day, the pre-release notice is out.  More info. Adobe Exploit Adobe has published a bulletin for ColdFusion that corrects a vulnerability that allows arbitrary code execution. CVSSv3 score of 9.8 Exploit PoC exis...

0
  523 Hits
  0 Comments

New Vulnerabilities Friday 14 July

New Alerts for Honeywell, Microsoft Edge, and Linux. Honeywell  Experion PKS, LX, and PlantCruise contains several vulnerabilities that allow DoS, privilege escalation, or RCE. Highest CVSSv3 score of 9.8More info. Microsoft  Microsoft has published an update for Edge that includes the latest chromium updates and three Edge specific updat...

0
  449 Hits
  0 Comments

New Vulnerabilities Thursday 13 July

Monthly Patches are out for Juniper Networks. New Alerts for Cisco, Apple (Exploit). Dell, SonicWall, Setelsa Security, NETGEAR, vm2, Wireshark, and Linux. Cisco  A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow a remote attacker to gain read permissions or limited write per...

0
  532 Hits
  0 Comments

New Vulnerabilities Wednesday 12 July

Monthly Patches are out for Microsoft and Adobe. New Alerts for Fortinet, Technicolor, Rockwell Automation, and Linux. It appears Apple pulled yesterday's RSR patch from the update servers. Microsoft Exploit Microsoft Monthly Patches are out, with 132 patched vulnerabilities, 9 rated Critical and 6 exploited in the wild. Highest CVSSv3 score of 9.8...

0
  426 Hits
  0 Comments

New Vulnerabilities Tuesday 11 July

Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Apple (Exploit), IBM, Mozilla, BD, and Linux. Monthly Patches for Microsoft and Adobe are expected this afternoon. Siemens  Siemens Monthly Patches are out, with 5 new bulletins and 12 updated bulletins. Of the new bulletins, highest CVSSv3 score of 9.8More info.D...

0
  673 Hits
  0 Comments

New Vulnerabilities Monday 10 July

New Alerts for SICK, Aruba, and Asterisk. Tomorrow is Patch Tuesday. SICK  Several security vulnerabilities have been found in the SICK ICR890-4. If exploited, these could allow a remote attacker to compromise the availability or confidentiality of the SICK ICR890-4. Highest CVSSv3 score of 8.6More info. Aruba  HPE Aruba Networking has re...

0
  362 Hits
  0 Comments

New Vulnerabilities Friday 07 July

New Alerts for PiiGAB, VMware, Atos, IBM, NetApp, and Linux. PiiGAB  M-Bus SoftwarePack 900s contains multiple vulnerabilities that allows a remote attacker to inject arbitrary commands, steal passwords, or trick valid users into executing malicious commands. CVSSv3 score of 9.8More info. VMware  VMware SD-WAN contains a bypass authentica...

0
  504 Hits
  0 Comments

New Vulnerabilities Thursday 06 July

Monthly Patches are out for Google Android, Pixel, Android Automotive OS, and Samsung. New Alerts for Cisco, Unitronics, Dell, and Linux. Google  Android Monthly Patches are out, with 27 vulnerabilities, 1 rated Critical and 26 rated High, plus Qualcomm, MediaTek, Arm, and Imagination Technologies patches.More info.Pixel Monthly Patches includ...

0
  390 Hits
  0 Comments

New Vulnerabilities Wednesday 05 July

New Alerts for Frauscher Sensortechnik, Poly, Dell, and Linux. Frauscher Sensortechnik  FDS001 for FAdC/FAdCi is vulnerable to a path traversal vulnerability of the web interface by a crafted URL without authentication. This enables a remote attacker to read all files on the filesystem of the FDS001 device. CVSSv3 score of 7.5 No patch, don't ...

0
  423 Hits
  0 Comments

New Vulnerabilities Tuesday 04 July

New Alerts for Bosch/Rexroth, Dell, Mozilla, and Linux. Bosch  The SLC-0-GPNT00300 is affected by a missing authentication for a critical function vulnerability in third-party software from SICK AG. Exploiting the vulnerability would allow a remote attacker to change the IP address of the device and affect the availability of the module. CVSSv...

0
  484 Hits
  0 Comments

New Vulnerabilities Monday 03 July

Monthly Patches are out for Qualcomm and MediaTek. New Alerts for SoftEther, Moxa, IBM, Dell, and NetApp. SoftEther  SoftEther VPN and PacketiX VPN contain multiple vulnerabilities in VPN Client function and Dynamic DNS Client function included in the VPN server. Highest CVSSv3 score of 8.1More info. And here. Qualcomm  Qualcomm Monthly P...

0
  545 Hits
  0 Comments

New Vulnerabilities Friday 30 June

New Alerts for Medtronic, Delta Electronics, GitLab, Microsoft Edge, IBM, Synology, Tenable, and Linux. Medtronic  Medtronic has identified a vulnerability in an optional messaging feature in the Paceart Optima cardiac device data workflow system. This vulnerability could result in the system's cardiac device data being deleted, stolen, or mod...

1
  687 Hits
  0 Comments

New Vulnerabilities Thursday 29 June

New Alerts for Mitsubishi Electric, IBM, NETGEAR, and Tenable. Mitsubishi Electric  An authentication bypass vulnerability exists in the MELSEC-F Series main modules. A remote attacker may be able to login to the product by sending specially crafted packets. CVSSv3 score of 7.5More info. IBM  IBM Watson Speech Services Cartridge and Disco...

0
  609 Hits
  0 Comments

New Vulnerabilities Wednesday 28 June

New Alerts for Supermicro, Bosch, and NETGEAR. Supermicro  A vulnerability in select supermicro boards may affect SMTP notification configurations. The vulnerability may allow an unauthenticated attacker to control user inputs such as the subject in the alert settings which may lead to arbitrary code execution. Supermicro rates this High.More ...

0
  391 Hits
  0 Comments

New Vulnerabilities Tuesday 27 June

New Alerts for Google Chrome, Hitachi Energy, IBM, and Linux. Google  Google has updated Chrome for Desktop to fix 4 security vulnerabilities.More info.Microsoft is aware. More info. Hitachi Energy  Hitachi Energy has published 4 new bulletins identifying vulnerabiltiies in OpenSSL in their products. Highest CVSSv3 score of 7.5Only 1 bull...

0
  453 Hits
  0 Comments

New Vulnerabilities Monday 26 June

New Alerts for WAGO and Dell. WAGO  A remote attacker with network access to port 502/TCP of the target device can cause a DoS by sending multiple specially crafted packets. CVSSv3 score of 7.5More info. Dell  Dell Networker remediation is available for multiple vulnerabilities in Spring Security that could be exploited by a remote attack...

0
  389 Hits
  0 Comments

New Vulnerabilities Friday 23 June

New Alerts for Crestron, Fortinet, Advantech, and Sierra Wireless. Crestron  Crestron x70 series of Touch Panels have inadvertently enabled diagnostic ports in firmware version 2.004.1026. This could potentially allow unauthorized individuals to run uncertified applications on the device.More info. Fortinet  A deserialization of untrusted...

0
  541 Hits
  0 Comments

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/