Skip to main content

CND News and Blog

New Vulnerabilities Friday 28 April

New Alerts for Illumina, NetApp, and Linux. Illumina  Instruments with Illumina Universal Copy Service v2 are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. Highest CVSSv3 score of 10More info. A...

0
  1003 Hits

New Vulnerabilities Thursday 27 April

New Alerts for Cisco, IBM, NetApp, and Dell. Cisco  A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. CVSSv3 score of 6.1More info. IBM  IBM App Connect Enterprise Certified ...

0
  937 Hits

New Vulnerabilities Wednesday 26 April

New Alerts for Keysight, Hitachi Energy, Tenable, and Linux. Keysight  Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid. A remote attacker could achieve RCE. CVSSv3 score of 9.8EOL, find a replacement.More info. Hitachi Energy  Multiple vulnerabilities i...

0
  1042 Hits

New Vulnerabilities Tuesday 25 April

New Alerts for Belden/Hirschmann, Microsoft Edge, IBM, and Linux. Belden  Hirschmann HiOS, Classic, HiSecOS, Wireless BAT-C2, Lite Managed, and Edge contain third-party software with vulnerabilities. Highest CVSSv3 score of 9.8More info. Microsoft  Microsoft has updated Edge with the latest chromium fixes.More info. IBM  IBM Db2 Grap...

0
  928 Hits

New Vulnerabilities Monday 24 April

Apparently it was a quiet weekend, I found no new vulnerabilities to report this morning.  Enjoy the great start to the week! Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar Page, ...

0
  695 Hits

New Vulnerabilities Friday 21 April

New Alerts for VMware and INEA. VMware  VMware Aria Operations for Logs contains several vulnerabilities, the worst of which allows a remote attacker to execute arbitrary code as root. Highest CVSSv3 score of 9.8More info. INEA  ME RTU contains an OS Command Injection vulnerability that could allow a remote attacker RCE. CVSSv3 score of 1...

0
  855 Hits

New Vulnerabilities Thursday 20 April

New Alerts for Cisco, PaperCut (Exploit), TIBCO, Microsoft Edge (Exploit), NetApp, and HCL Software.  Cisco  Cisco has published 6 new bulletins and 2 updated bulletins. Of the new bulletins, 2 are rated Critical, 2 rated High, and 2 rated Medium. Highest CVSSv3 score of 9.9More info. A vulnerability in the external authentication mechani...

0
  945 Hits

New Vulnerabilities Wednesday 19 April

New Alerts for F5, vm2, Google Chrome (Exploit), and Linux. F5  BIG-IP Next SPK and F5OS contain a vulnerability in urllib3 that allows a remote attacker to inject additional HTTP headers via the HTTP method and perform a smuggling attack and/or allow a client to bypass HTTP headers with security purpose. Highest CVSSv3 score of 6.5.More info....

0
  814 Hits

New Vulnerabilities Tuesday 18 April

Oracle Quarterly Patches are out this afternoon.  New Alerts for Philips, IBM, Pale Moon, and Linux.  Philips Philips has identified several products vulnerable to the Windows CLFS issue that is being actively exploited. CVSSv3 score of 7.8More info. OracleOracle quarterly patches are out with 414 new security patches, 284 are remotely ex...

0
  1090 Hits

New Vulnerabilities Monday 17 April

New Alerts for HP, Omron (Exploit), Google Chrome (Exploit), and Microsoft Edge (Exploit.)  Tomorrow is Oracle Quarterly Patches, the pre-release is out, see the link below. HP  HP Device Manager could potentially allow command injection and/or elevation of privileges. Highest CVSSv3 score of 9.8More info. Omron Exploit FINS is a protocol...

0
  769 Hits

New Vulnerabilities Friday 14 April

New Alerts for Mitsubishi Electric India, B&R, Dell, NetApp, and Linux. Mitsubishi Electric India  Mitsubishi Electric India Ethernet communication Extension unit GC-ENET-COM contains a vulnerability that leads to a communication error and may result in a DoS. CVSSv3 score of 7.5 More info. B&R  VC4 Visualization contains several ...

0
  952 Hits

New Vulnerabilities Thursday 13 April

Monthly Patches for Juniper Networks are out. New Alerts for FANUC, NTP, IBM, Dell, Wireshark, and Linux.  FANUC  FANUC ROBOGUIDE-HandlingPRO contains a Path Traversal vulnerability that could allow a remote attacker to read and/or overwrite files on the system running the affected software. CVSSv3 score of 6.8More info. Juniper Networks ...

0
  935 Hits

New Vulnerabilities Wednesday 12 April

Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Mozilla, SICK, Hikvision, and Linux. Microsoft Exploit Microsoft Monthly Patches are out with fixes for 114 vulnerabilities, 7 of which are Critical and 1 EoP vulnerability being exploited. Highest CVSSv3 score of 9.8More info. And here. And here. Adobe  In their Monthl...

0
  981 Hits

New Vulnerabilities Tuesday 11 April

Monthly Patches are out for Siemens, Schneider Electric, SAP, and Google Pixel. New Alerts for Apple (Exploit), TRENDnet, and Linux.      This afternoon Microsoft and Adobe Monthly Patches should be out. Tomorrow there might be Palo Alto Networks patches. Siemens  Siemens Monthly Patches are out with 13 new bulletins and 32 upda...

0
  840 Hits

New Vulnerabilities Monday 10 April

New Alert for Apple (Exploit). Apple has published updates for Safari, iOS, iPadOS, and macOS. These contain actively exploited vulnerabilities. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardr...

0
  880 Hits

New Vulnerabilities Friday 07 April

New Alerts for Trellix, ICL (Exploit), Microsoft, IBM, and Open vSwitch. Trellix  ePolicy Orchestrator (ePO) contains a vulnerability in APR-util that allows an attacker to write beyond bounds of a buffer. CVSSv3 score of 9.8More info. ICL Exploit On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 devices, remote attackers can overwrite, delet...

0
  973 Hits

New Vulnerabilities Thursday 06 April

Monthly Patches are out for MediaTek. New Alerts for Cisco, NetApp, WithSecure, Mitel, and Linux.  Cisco  Cisco has published 13 new bulletins. 3 rated High, 9 rated Medium, 1 Informational. Highest CVSSv3 score of 8.8More info.A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow a re...

0
  897 Hits

New Vulnerabilities Wednesday 05 April

New Alerts for Sophos, Google Chrome, Dell, and Nexx. Sophos  Sophos Web Appliance has been updated to fix 3 vulnerabilities, one of them rated Critical and allowing a remote attacker to obtain RCE. Highest CVSSv3 score of 9.8More info. Google  Google has published an update for Chrome for Desktop with 16 security fixes included. More inf...

0
  1019 Hits

New Vulnerabilities Tuesday 04 April

Monthly Patches are out for Google Android, Google Automotive, and Samsung Mobile. New Alerts for Samsung Semiconductor, HP, WithSecure, Ivanti Apache, and Linux. Google  Android Monthly Patches are out, with 30 patched vulnerabilities with 2 rated Critical, plus Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm updates.More info.A...

0
  840 Hits

New Vulnerabilities Monday 03 April

Monthly Patches are out for Qualcomm. New Alerts for ABB, IBM, and Linux. ABB A vulnerability regarding the exposure of sensitive information over the Flow-X web API has been reported. A remote attacker could exploit this vulnerability to obtain an overview of the usernames which can login into the device and device information. CVSSv3 score of 5.3...

0
  988 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/