Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 11 July

Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Apple (Exploit), IBM, Mozilla, BD, and Linux. Monthly Patches for Microsoft and Adobe are expected this afternoon. Siemens  Siemens Monthly Patches are out, with 5 new bulletins and 12 updated bulletins. Of the new bulletins, highest CVSSv3 score of 9.8More info.D...

0
  1072 Hits

New Vulnerabilities Monday 10 July

New Alerts for SICK, Aruba, and Asterisk. Tomorrow is Patch Tuesday. SICK  Several security vulnerabilities have been found in the SICK ICR890-4. If exploited, these could allow a remote attacker to compromise the availability or confidentiality of the SICK ICR890-4. Highest CVSSv3 score of 8.6More info. Aruba  HPE Aruba Networking has re...

0
  801 Hits

New Vulnerabilities Friday 07 July

New Alerts for PiiGAB, VMware, Atos, IBM, NetApp, and Linux. PiiGAB  M-Bus SoftwarePack 900s contains multiple vulnerabilities that allows a remote attacker to inject arbitrary commands, steal passwords, or trick valid users into executing malicious commands. CVSSv3 score of 9.8More info. VMware  VMware SD-WAN contains a bypass authentica...

0
  952 Hits

New Vulnerabilities Thursday 06 July

Monthly Patches are out for Google Android, Pixel, Android Automotive OS, and Samsung. New Alerts for Cisco, Unitronics, Dell, and Linux. Google  Android Monthly Patches are out, with 27 vulnerabilities, 1 rated Critical and 26 rated High, plus Qualcomm, MediaTek, Arm, and Imagination Technologies patches.More info.Pixel Monthly Patches includ...

0
  864 Hits

New Vulnerabilities Wednesday 05 July

New Alerts for Frauscher Sensortechnik, Poly, Dell, and Linux. Frauscher Sensortechnik  FDS001 for FAdC/FAdCi is vulnerable to a path traversal vulnerability of the web interface by a crafted URL without authentication. This enables a remote attacker to read all files on the filesystem of the FDS001 device. CVSSv3 score of 7.5 No patch, don't ...

0
  869 Hits

New Vulnerabilities Tuesday 04 July

New Alerts for Bosch/Rexroth, Dell, Mozilla, and Linux. Bosch  The SLC-0-GPNT00300 is affected by a missing authentication for a critical function vulnerability in third-party software from SICK AG. Exploiting the vulnerability would allow a remote attacker to change the IP address of the device and affect the availability of the module. CVSSv...

0
  890 Hits

New Vulnerabilities Monday 03 July

Monthly Patches are out for Qualcomm and MediaTek. New Alerts for SoftEther, Moxa, IBM, Dell, and NetApp. SoftEther  SoftEther VPN and PacketiX VPN contain multiple vulnerabilities in VPN Client function and Dynamic DNS Client function included in the VPN server. Highest CVSSv3 score of 8.1More info. And here. Qualcomm  Qualcomm Monthly P...

0
  944 Hits

New Vulnerabilities Friday 30 June

New Alerts for Medtronic, Delta Electronics, GitLab, Microsoft Edge, IBM, Synology, Tenable, and Linux. Medtronic  Medtronic has identified a vulnerability in an optional messaging feature in the Paceart Optima cardiac device data workflow system. This vulnerability could result in the system's cardiac device data being deleted, stolen, or mod...

1
  1243 Hits

New Vulnerabilities Thursday 29 June

New Alerts for Mitsubishi Electric, IBM, NETGEAR, and Tenable. Mitsubishi Electric  An authentication bypass vulnerability exists in the MELSEC-F Series main modules. A remote attacker may be able to login to the product by sending specially crafted packets. CVSSv3 score of 7.5More info. IBM  IBM Watson Speech Services Cartridge and Disco...

0
  1140 Hits

New Vulnerabilities Wednesday 28 June

New Alerts for Supermicro, Bosch, and NETGEAR. Supermicro  A vulnerability in select supermicro boards may affect SMTP notification configurations. The vulnerability may allow an unauthenticated attacker to control user inputs such as the subject in the alert settings which may lead to arbitrary code execution. Supermicro rates this High.More ...

0
  825 Hits

New Vulnerabilities Tuesday 27 June

New Alerts for Google Chrome, Hitachi Energy, IBM, and Linux. Google  Google has updated Chrome for Desktop to fix 4 security vulnerabilities.More info.Microsoft is aware. More info. Hitachi Energy  Hitachi Energy has published 4 new bulletins identifying vulnerabiltiies in OpenSSL in their products. Highest CVSSv3 score of 7.5Only 1 bull...

0
  840 Hits

New Vulnerabilities Monday 26 June

New Alerts for WAGO and Dell. WAGO  A remote attacker with network access to port 502/TCP of the target device can cause a DoS by sending multiple specially crafted packets. CVSSv3 score of 7.5More info. Dell  Dell Networker remediation is available for multiple vulnerabilities in Spring Security that could be exploited by a remote attack...

0
  772 Hits

New Vulnerabilities Friday 23 June

New Alerts for Crestron, Fortinet, Advantech, and Sierra Wireless. Crestron  Crestron x70 series of Touch Panels have inadvertently enabled diagnostic ports in firmware version 2.004.1026. This could potentially allow unauthorized individuals to run uncertified applications on the device.More info. Fortinet  A deserialization of untrusted...

0
  995 Hits

New Vulnerabilities Thursday 22 June

New Alerts for Apple (Exploit), Cisco, VMware, Juniper, NetApp, and Linux. Apple Exploit Apple has published security patches for Safari, iOS, iPadOS, macOS, and watchOS. Three vulnerabilities are actively exploited, 2 of those allow code execution. Highest CVSSv3 score of 9.8More info. And here. Cisco  Multiple vulnerabilities in the web-base...

0
  789 Hits

New Vulnerabilities Wednesday 21 June

New Alerts for Enphase, SICK, IBM, BIND, Xerox, and Linux. Enphase  Enphase Installer Toolkit has hard coded credentials embedded in binary code in the Android application. A remote attacker can exploit this and gain access to sensitive information. CVSSv3 score of 8.6More info. SICK  Vulnerabilities exist in the SICK EventCam App, that c...

0
  816 Hits

New Vulnerabilities Tuesday 20 June

New Alerts for Mitsubishi Electric, IBM, Zyxel, D-Link, Siren, ASUS, and Linux. Mitsubishi Electric  Several MELSEC IQ products have been added to a previous bulletin. A remote attacker can login to FTP server or Web server due to plaintext storage of passwords. CVSSv3 score of 7.5More info. IBM  IBM Cloud Pak for Network Automation 2.4.7...

0
  987 Hits

New Vulnerabilities Monday 19 June

New Alert for HPE. HPE  The MC990X and UV300 RMC component had an outdated OpenSSL and inadequate default configuration. Highest CVSSv3 score of 7.5More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of o...

0
  735 Hits

New Vulnerabilities Friday 16 June

New Alerts for Progess MOVEit, NetApp, and Node.js. Progress  Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges and potential unauthorized access to the environment. CVSSv3 score of 9.8More info. NetApp  NetApp has published 6 new bulletins identifying vulnerabilities in third-party softwar...

0
  981 Hits

New Vulnerabilities Thursday 15 June

Monthly Patches are out for Palo Alto Networks. New Alerts for Hikvision, Microsoft (Edge), QNAP, Lenovo, Riello UPS, and Linux. Palo Alto Networks  Palo Alto Networks Monthly Patches include 2 bulletins, both rated Medium. Highest CVSSv3 score of 6.7More info. Hikvision  Some of Hikvision's access control/intercom products contain two se...

0
  940 Hits

New Vulnerabilities Wednesday 14 June

Monthly Patches are out for Microsoft, Adobe, and Google Pixel. New Alerts for Rockwell Automation, Google Chrome, IBM, and Linux. Microsoft  Microsoft has published their Monthly Patches with 73 vulnerabilities. Six of these vulnerabilities are rated as Critical, in Visual Studio, .net, and Windows PGM. Highest CVSSv3 score of 9.8More info. A...

0
  793 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/