CND News and Blog
New Alerts for Apple (Exploit), Cisco, Atos, Google, Microsoft (Exploit), Atlassian (Exploit), HP, Wireshark, and Linux Apple Exploit Apple has published updates for actively exploited vulnerabilties in iOS and iPadOS. CVSSv3 score of 8.8More info. And here. Cisco A vulnerability in Cisco Emergency Responder could allow a remote attacke...
New Alerts for SICK, Samsung, and Google Chrome. SICK SICK SIM1012 has all Ethernet ports are open by factory default. This could potentially allow a remote attacker to impact the availability, confidentiality, and integrity of the SICK SIM1012. CVSSv3 score of 9.8Remediation only, close the ports.More info.Multiple SICK products includ...
Monthly Patches are out for MediaTek and Google Android. New Alerts for IBM and Linux. MediaTek MediaTek has published their Monthly Patches with 3 vulnerabilities rated High, 9 rated Medium.More info. Google Google Monthly Patches for Android are out, with 1 Critical vulnerability, and 31 High, with Arm, MediaTek, Unisoc, and Qualcomm ...
Monthly Patches are out for Qualcomm. New Alerts for Exim (0-Day), BD, Microsoft Edge (Exploit), and NetApp. Exim 0-Day A vulnerability in Exim allows remote attackers to execute arbitrary code on affected installations of Exim. CVSSv3 score of 9.8This was released as a 0-day.More info. And here. BD BD has published security updates for Phoen...
New Alerts for Progress Software, Dell, and Linux. Progress Software Vulnerabilities in the WS_FTP Server Ad hoc Transfer Module and in the WS_FTP Server manager interface have been identified. Highest CVSSv3 score of 10.More info. Dell Dell Container Storage Modules remediation is available for multiple security vulnerabilities that co...
New Alerts for Cisco, Google Chrome (Exploit), IBM, HPE, and Mozilla (Exploit). Cisco Cisco has published 15 new bulletins, 1 rated Critical, 7 rated High, and 7 rated Medium. Highest CVSSv3 score of 9.8More info.Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager could allow an attacker to access an affected instance or cause a DoS on ...
New Alerts for Baker Hughes, Squid, Apple, Belden, Juniper Networks (Exploit), Mozilla, and Linux. Baker Hughes Bently Nevada 3500 Rack (TDI Firmware) contains several vulnerabilities including exposure of sensitive information, cleartext transmission of sensitive information, and authentication bypass by capture-replay. Highest CVSSv3 score ...
New Alerts for Hitachi Energy, IBM, Dell, and Linux. Hitachi Energy Hitachi Energy includes libexpat open-source software in their AFx series products. There are multiple vulnerabilities in the libexpat component that allow a remote attacker to compromise the targeted devices availability, integrity, and confidentiality. Highest CVSSv3 score ...
New Alerts for WAGO, BD, Elasticsearch, and Linux. WAGO WAGO products e!COCKPIT and WAGO-I/O-Pro both include vulnerable WIBU Systems Codemeter product. Highest CVSSv3 of 9.8More info. BD BD has published Microsoft and third-party software updates for FACSCanto 10-Color System, FACSCelesta, FACSAria, FACSCanto II System, LSRFortessa, Fo...
New Alerts for Apple (Exploit), Real Time Automation (Exploit), D-Link (Exploit), QNAP, NetApp, and Linux. Apple Exploit Apple has updated iOS, iPadOS, watchOS, macOS, and Safari to fix Exploited, Critical vulnerabilities.More info. Real Time Automation Exploit Real Time Automation 460MCBS contains a Cross-site Scripting vulnerability that co...
New Alerts for Ingeteam, Frauscher Sensortechnik, Dell, Rockwell Automation, and Linux. Ingeteam Three vulnerabilities have been identified in Ingeteam INGEPAC DA 3451 and INGEPAC EF MD. Highest CVSSv3 score of 8.6More info. Frauscher Sensortechnik Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi are prone to multiple vulnerabilities ...
New Alerts for Omron, Atlassian, BIND, and Linux. Omron Omron CJ/CS/CP series programmable logic controllers use the FINS protocol, which is vulnerable to brute-force attacks. The controllers do not enforce any rate limit on password guesses to password-protected memory regions. CVSSv3 score of 7.5More info. Atlassian Four high-severity...
Updates for Phoenix Contact, Google Pixel, IBM, Apple, and Linux. Phoenix Contact Multiple products are affected by WIBU Codemeter vulnerabilities. Highest CVSSv3 score of 10.More here. Google Google updates for Pixel include Android security patches and 1 Pixel-specific security vulnerability rated High, currently being exploited.More ...
New Alerts for Open5Gc, NetApp, and Linux. Open5Gc Free5Gc contains a CSRF vulnerability that could allow a remote attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". CVSSv3 score of 9.8 More info. And here. NetApp NetApp has published 14 new bulletins identifying vul...
New Alerts for IBM, HPE, WithSecure, BD, and Linux. IBM Multiple vulnerabilities exist in jackson-databind-2 used by IBM Application Performance Management. Highest CVSSv3 score of 9.8More info.Due to use of Golang Go, IBM Cloud Pak for Multicloud Management Monitoring is vulnerable to multiple vulnerabilities. Highest CVSSv3 score of 9.8More...
New Alerts for Cisco, Palo Alto Networks, Fortinet, IBM, BD, and curl. Cisco Cisco has released 6 bulletins, 5 rated Medium and 1 Informational. Highest CVSSv3 score of 6.7More info.A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow a remote attacker to cause a DoS. CVSSv3 score of 4.3More ...
Monthly Patches are out for Microsoft and Adobe. New Alerts for Microsoft Edge (Exploit), BlackBerry, Google Chrome (Exploit), Rockwell Automation, ASUS, and Mozilla (Exploit). Microsoft Exploit Microsoft Monthly Patches include fixes for 66 vulnerabilities, 5 rated Critical, 2 being actively exploited. Highest CVSSv3 score of 8.8More info. And her...
Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Microsoft Edge (0-Day), Apple (exploit), Zoom, and Linux.Monthly Patches for Microsoft and Adobe are expected this afternoon. Siemens Siemens Monthly Patches contain 7 new bulletins and 14 updated bulletins. Of the new bulletins, highest CVSSv3 score of 9.0More i...
New Alerts for Open5GS, IBM, NetApp, and Linux. Open5GS Open5GS contains 4 vulnerabilities that could allow a remote attacker to cause DoS or retrieve device information. Highest CVSSv3 score of 7.5More info. IBM IBM App Connect Enterprise is vulnerable to a remote attack and a denial of service due to third-party software. Highest CVSS...
New Alerts for Apple (Exploit), Socomec, Dover Fueling, Microsoft Edge, Dell, and HPE. Apple Exploit Apple has published updates for iOS, iPadOS, macOS, and watchOS. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Apple is aware that 2 of the vulnerab...
By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/