CND News and Blog
New Alerts for Cisco, ClamAV, Mitsubishi Electric, Moxa, Atlassian, IBM, and Synology. Cisco Cisco has published 17 new bulletins, 5 rated High and 12 rated Medium. Highest CVSSv3 score of 8.1More info.Secure Endpoint products are affected by a ClamAV vulnerability allowing a DoS. CVSSv3 score of 7.5 More info. And here. ClamAV ClamAV h...
New Alerts for Google Chrome, BD, Meinberg, and Linux. Google Google has published an update for Chrome for Desktop that includes 26 security fixes.More info.Microsoft is aware. More info. BD BD has published security patches for Pyxis, Data Agent, CCE, Alaris, and IDM.More info. Meinberg LANTIME firmware has been updated to inclu...
New Alerts for Zyxel, NetApp, and Linux. Zyxel Zyxel has released updates for several switches to fix a DoS vulnerability.More info. NetApp NetApp has published 9 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8. No patches yet.More info. Linux SUSE has updat...
New Alert for Linux. Linux SUSE has updated the kernel and kernel firmware. More info.OpenSUSE has updated the kernel and kernel firmware. More info.Debian has updated the kernel and microcode. More info.Ubuntu has updated the kernel and microcode. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securityw...
New Alert for Belden. Happy Friday! Belden Hirschmann Wireless OWL contains a vulnerability in zlib. CVSSv3 score of 9.8More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar ...
New Alerts for Xerox, Dell, Softing (0-Day), and Linux. Xerox Xerox has updated FreeFlow Print Server with the latest 3rd-party software updates. Highest CVSSv3 score of 9.8More info. And here. Dell Security Update for Dell ESI (Enterprise Storage Integrator) for SAP LAMA multiple security vulnerabilities. Dell rates this Critical.More ...
Monthly Patches are out for Microsoft and Adobe. New Alerts for Rockwell Automation, IBM, Dell, Hitachi, and Linux. Microsoft Exploit Microsoft Monthly Patches are out, with patches for 88 vulnerabilities, 6 are Critical, and 2 are being exploited. Highest CVSSv3 score of 9.8More info. And here. And here. Adobe Adobe Monthly Patches include p...
Monthly Patches are out for Google Android, Google Pixel, Samsung, Siemens, Schneider Electric, and SAP. New Alerts for Microsoft Edge, Zoom, Phoenix Contact, and Linux. Microsoft and Adobe Monthly Patches are expected this afternoon. Google Google Android Monthly Patches are out, with 37 addressed vuln...
Monthly Patches are out for Qualcomm and MediaTek. New Alerts for Dell, NetApp, and Linux. Tomorrow will be Patch Day for Google (Android/Pixel/Automotive OS), Samsung, Microsoft, Adobe, SAP, Siemens, and Schneider Electric. Qualcomm Qualcomm Monthly Patches are out, with 13 vulnerabilities, 4 rated Critical, 6 rate...
New Alerts for TEL-STER, NetApp, WithSecure, Ivanti, and Linux. TEL-STER External input could be used on TEL-STER TelWin SCADA WebInterface which could allow a remote attacker to read files on the system. CVSSv3 score of 7.5More info. NetApp NetApp has published 11 new bulletins identifying vulnerabilities in third-party software includ...
New Alerts for Cisco, Mitsubishi Electric, Google, Dell, Veritas, Mozilla, Tenable, and Linux. Cisco Cisco has published 2 new bulletins, both rated Medium.More info.A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow a remote attacker to bypass a configured rule, allowing traffic onto ...
New Alerts for APSystems, HPE, F5, Mozilla, GitLab, ZKTeco, and Linux. APSystems OS command injection affects Altenergy Power Control software via shell metacharacters in the timezone parameter. CVSSv3 score of 9.8No response from vendor.More info. HPE Potential security vulnerabilities has been identified in HPE Fabric OS. These vulner...
New Alerts for Omron, IBM, Hitachi, NetApp, and Linux. Omron Vulnerabilities related to NicheStack TCP/IP stack exist in the EtherNet/IPTM option board for Multi-function Compact Inverter 3G3MX2. An attacker may use these vulnerabilities to perform RCE, DoS, or obtain sensitive information. Highest CVSSv3 score of 9.8No patch.More info. IBM&n...
New Alerts for WAGO, IBM, Synology, Microsoft Azure, and Linux. WAGO Multiple WAGO devices are prone to vulnerabilites in the used CODESYS V3 framework. Highest CVSSv3 score of 8.8No patch yet.More info. IBM Multiple vulnerabilities were addressed in IBM Cloud Pak for Watson AIOps. Highest CVSSv3 score of 9.8More info.Multiple security ...
New Alerts for PTC, QNAP, and Linux. PTC A remote attacker can perform a DoS attack on KEPServerEX by performing resource exhaustion. CVSSv3 score of 7.5No patch yet.More info. And here. QNAP An uncontrolled resource consumption vulnerability has been reported to affect multiple QNAP operating systems. If exploited, the vulnerability al...
New Alerts for Veritas, Fujitsu, Mitsubishi Electric, and Linux. Veritas A vulnerability was discovered in Veritas NetBackup Snapshot Manager which allowed untrusted clients to interact with the RabbitMQ service. CVSSv3 score of 9.8More info. Fujitsu Real-time Video Transmission Gear IP series provided by Fujitsu Limited uses hard-coded...
New Alerts for Crestron, Johnson Controls, Emerson, Bosch, B&R Automation, HPE Aruba (Exploit), Tenable, and Linux. Crestron Aan issue exists in the 3-Series Control Systems where crafting and sending a specific BACnet packet can crash the system.More info. And here. Johnson Controls Johnson Controls IQ Wifi 6 contains a vulnerabili...
New Alerts for Apple (Exploit), Ivanti (Exploit), Belden, Hitachi Energy, IBM, NetApp, PaperCut, WIBU, and Linux. Apple Exploit Apple has published updates for Safari, iOS, iPadOS, macOS, tvOS, and watchOS. Highest CVSSv3 score of 9.8At least two vulnerabilities have been exploited.More info. And here. Ivanti Exploit An authentication bypass vulner...
New Alert for Microsoft Edge. Microsoft Microsoft has updated Edge to include all chromium updates, and 3 additional Edge specific vulnerabilities.More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of o...
New Alerts for Digi, HP, Mozilla, Google ChromeOS, and Linux. Digi Digi has patched the NDS and NET+OS product lines to fix an incompletely patched Ripple20 vulnerability. CVSSv3 score of 9.0More info. HP Certain HP LaserJet Pro print products are potentially vulnerable to an elevation of privilege and/or information disclosure related ...
By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/