Skip to main content

CND News and Blog

New Vulnerabilities Friday 07 June

New Alerts for Emerson, PHP, and Samsung. TGIF, seems like it's been Friday all week long! Emerson  CISA is reporting Ovation as vulnerable to OT:ICEFALL. Highest CVSSv4 score of 9.3More info. PHP  PHP has been updated for several security vulnerabilities, including a RCE. It's not clear if this impacts more than XAMPP on Windows in Japan...

0
  579 Hits

New Vulnerabilities Thursday 06 June

New Alerts for Cisco, NetApp, Bitdefender, and Linux. Cisco  Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow a remote attacker to perform a stored XSS attack by exploiting a RFI vulnerability or perform a SSRF attack. Highest CVSSv3 score of 7.2More info. NetApp  NetApp has published 10 new bull...

0
  514 Hits

New Vulnerabilities Wednesday 05 June

New Alerts for NetApp, IBM, and Linux. NetApp  NetApp has published 8 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8Two have patches.More info. IBM  Multiple vulnerabilities have been identified in Apache Commons Collections, which is used in IBM Engineering Lifecy...

0
  382 Hits

New Vulnerabilities Tuesday 04 June

Monthly Patches are out for Google Android and Samsung. New Alerts for Microsoft Edge, Codesys, Mitsubishi Electric, Zyxel, and Linux. Google  Monthly Patches are out for Android with 12 addressed vulnerabilities, plus Arm, MediaTek, and Qualcomm patches.More info. Samsung  Samsung Monthly Patches are out with 22 SVEs addressed vulnerabil...

0
  478 Hits

New Vulnerabilities Monday 03 June

Monthly Patches are out for Qualcomm and MediaTek. New Alerts for Checkpoint (Exploit), Apache OfBiz, Apache Wicket, ifm, Progress, and Linux. Checkpoint Exploit Checkpoint has determined the Quantum Spark Gateways are vulnerable to the information disclosure security vulnerability as well.More info. Apache  Apache OfBiz contains a path traver...

0
  465 Hits

New Vulnerabilities Friday 31 May

New Alerts for Google Chrome, Westermo, BD, IBM, and Linux. Google  Google has updated Chrome for Desktop to fix 11 security vulnerabilities.More info. Westermo  EDW-100 contains Use of Hard-coded Passwordand Insufficiently Protected Credentials vulnerabilities that could allow a remote attacker to access the device using hardcoded creden...

0
  431 Hits

New Vulnerabilities Thursday 30 May

New Alerts for Checkpoint (Exploit), Baxter, Carrier, Dell, F5, and Linux. Checkpoint Exploit Checkpoint Quantum Security Gateway has an actively exploited vulnerability in Security Gateways with IPsec VPN in Remote Access VPN community and the Mobile Access software blade. CVSSv3 score of 8.6More info. And here. Baxter  Welch Allyn Connex Spo...

0
  518 Hits

New Vulnerabilities Wednesday 29 May

New Alerts for TIBCO, Xerox, Baxter, Dell, IBM, Campbell Scientific, and Linux. TIBCO  Managed File Transfer Platform Server for Unix and z/Linux contain a vulnerability that allows Platform Server clients to bypass user-id/password authentication and transfer files as root or execute commands as root. CVSSv3 score of 9.8More info. Xerox ...

0
  563 Hits

New Vulnerabilities Tuesday 28 May

New Alerts for HPE, Hitachi, and Linux. HPE  Security vulnerabilities have been identified with Tomcat-based Servlet Engine on HP-UX 11i. These vulnerabilities could be locally and remotely exploited to create a DoS, unauthorized read access to sensitive data, unauthorized access to server, and disclosure of information. Highest CVSSv3 score o...

0
  499 Hits

New Vulnerabilities Monday 27 May

New Alerts for Omron, Microsoft Edge (Exploit), IBM, F5, Synology, and NetApp. Omron  Due to the multiple vulnerabilities caused by OpenSSL in NJ/NX-series Machine Automation Controllers, information may be leaked or cause a DoS. Highest CVSSv3 score of 7.5More info.Due to an Insufficient Verification of Data Authenticity vulnerability which e...

0
  508 Hits

New Vulnerabilities Friday 24 May

New Alerts for AutomationDirect, IBM, Google Chrome, D-Link, Mitel, and Linux. AutomationDirect  AutomationDirect Productivity PLCs contains multiple vulnerabilities. Highest CVSSv3 score of 9.3More info. IBM  IBM Security Guardium is affected by multiple vulnerabilities. Highest CVSSv3 score of 9.8More info.IBM Spectrum Protect Plus Cont...

0
  615 Hits

New Vulnerabilities Thursday 23 May

New Alerts for Cisco, lighttpd, Progress, BD, and GitLab. Cisco  Cisco has published 5 new bulletins and 3 updated bulletins. Of the new bulletins, highest CVSSv3 score of 5.8More info.A vulnerability in the activation of an ACL on ASA and FTD software could allow a remote attacker to bypass the protection that is offered by a configured ACL o...

0
  478 Hits

New Vulnerabilities Wednesday 22 May

New Alerts for Veeam, Fluent Bit, Atlassian, Github, Google Chrome, and Linux. Veeam  Several vulnerabilities have been patched in Veeam Backup Enterprise Manager, the worst of which allows a remote attacker to log in to the Veeam Backup Enterprise Manager web interface as any user. Highest CVSSv3 score of 9.8More info. Fluent Bit  A crit...

0
  471 Hits

New Vulnerabilities Tuesday 21 May

New Alert for IBM.  IBM  IBM Cloud Pak for Network Automation has been updated to address multiple security vulnerabilities. Highest CVSSv3 score of 9.8More info.IBM has released a fix for IBM Db2 REST in response to multiple vulnerabilities. Highest CVSSv3 score of 9.8More info. Security Wizardry Cyber Threat Intelligence - The Radar Pag...

0
  575 Hits

New Vulnerabilities Monday 20 May

New Alerts for Dell, Asterisk, Mozilla, and Cerberus. Dell  Dell has updated NetWorker Runtime Environment to fix several Java SE Embedded vulnerabilities. Dell rates this Critical.More info. Asterisk  A vulnerability allows all unauthorized SIP requests to be identified as PJSIP Endpoint of local asterisk server. CVSSv3 score of 5.8More ...

0
  520 Hits

New Vulnerabilities Friday 17 May

New Alerts for SolarWinds, Microsoft Edge (exploit), HPE, NetApp, IBM, MongoDB, and Linux. TGIF! SolarWinds  The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. This vulnerability allows access to the RabbitMQ management console. CVSSv3 score of 8.6More info. Microsoft Exploit ...

0
  529 Hits

New Vulnerabilities Thursday 16 May

New Alerts for Cisco, D-Link (0-Day), Google Chrome (Exploit), Phoenix Contact, Wireshark, F5, and Linux. Cisco  Cisco has published 8 new bulletins, three rated High and four rated Medium. Highest CVSSv3 score of 7.8More info. Multiple vulnerabilities in the web-based management interface of AsyncOS Software for Secure Email and Web Manager; ...

0
  441 Hits

New Vulnerabilities Wednesday 15 May

Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Mozilla, Aruba, Bosch, and Linux. Microsoft  Microsoft Monthly Patches are out, with 67 patched vulnerabilities, 1 rated Critical, and 1 other actively exploited. Highest CVSSv3 score of 8.8More info. And here.Microsoft has patched Edge for the currently exploited chrom...

0
  628 Hits

New Vulnerabilities Tuesday 14 May

Monthly Patches are out for Siemens and SAP. New Alerts for Apple, Google Chrome (Exploit), Extreme Networks, Cacti, and Linux. Apple  Apple has published updates for iOS, iPadOS, macOS, watchOS, tvOS, and Safari. One exploited vulnerability is patched for older versions of macOS and iOS.More info. And here. Siemens  Siemens Monthly Patch...

0
  604 Hits

New Vulnerabilities Monday 13 May

New Alerts for Microsoft Edge (exploit), PowerDNS, Apache OFBiz, Belden, NetApp, and Linux. Microsoft Exploit Microsoft has updated Edge with the latest chromium vulnerability fixes and one Edge-specific fix.There are active exploits.More info. PowerDNS  When incoming DNS over HTTPS support is enabled using the nghttp2 provider a remote attack...

0
  592 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/