Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 16 May

New Alerts for SICK, IBM, Hitachi, vm2, and Linux. SICK  Multiple security vulnerabilities in the SICK FTMg device that could allow a remote attacker to impact the availabiltiy or confidentaility of the FTMg device. Highest CVSSv3 score of 7.5More info. IBM  IBM Edge Application Manager addresses security vulnerabilities in open source so...

0
  823 Hits

New Vulnerabilities Monday 15 May

New Alerts for OPC, IBM, Tenable, Vyper, and Linux. OPC  OPC has resolved a vulnerability in the OPC UA Legacy Java Stack that enables a remote attacker to block OPC UA server applications so that they can no longer serve client application. CVSSv3 score of 7.5More info. IBM  IBM Cloud Pak for Network Automation addresses multiple securit...

1
  1076 Hits

New Vulnerabilities Friday 12 May

New Alerts for SDG Technologies, Rockwell Automation, Teltonika, IBM, Dell, and Netapp. SDG Technologies  The PnPSCADA system contains a critical unauthenticated error-based PostgreSQL Injection vulnerability allowing a remote attacker to engage with the underlying database seamlessly and passively. CVSSv3 score of 9.8No patch yet.More info. R...

1
  897 Hits

New Vulnerabilities Thursday 11 May

Monthly patches are out for Palo Alto networks. New Alerts for F5, Mozilla, Tenda (Exploit), and Linux. Palo Alto Networks  Palo Alto Networks Monthly Patches includes 2 bulletins, highest CVSSv3 score of 6.5More info. F5  F5OS contains a vulnerability in python that can by used by a remote attacker to perform RCE. Highest CVSSv3 score of...

0
  1010 Hits

New Vulnerabilities Wednesday 10 May

New alerts for Aruba, IBM, Dell, Mozilla, Tenable, and Linux. Aruba  Aruba has released patches for Aruba access points running InstantOS and ArubaOS 10 that address multiple security vulnerabilities that could allow a remote attacker to execute code or cause a DoS. Highest CVSSv3 score of 9.8More info. IBM  Multiple issues were identifie...

0
  1180 Hits

New Vulnerabilities Tuesday 09 May - Part 2

Monthly Patches are out for Microsoft, Adobe, and Siemens. Microsoft  Microsoft Monthly Patches include fixes for 49 vulnerabilities, 6 rated Critical and 2 being exploited. Exploited vulnerabilities include Secure Boot Security feature bypass, and Win32k EoP. Highest CVSSv3 score of 9.8More info. And here. And here.NFS contains a RCE vulnerab...

0
  893 Hits

New Vulnerabilities Tuesday 09 May

Monthly Patches are out for Schneider Electric and SAP. New Alert for F5.     Monthly Patches for Siemens, Microsoft, and Adobe expected this afternoon.  Palo Alto Networks might put out patches tomorrow. Schneider Electric  Schneider Electric Monthly Patches are out, with 4 new bulletins and 2 updated bulletins. Of th...

0
  875 Hits

New Vulnerabilities Monday 08 May

New Alerts for SICK, Microsoft Edge, and NetApp. SICK  SICK discovered a vulnerability in several Flexi Classic and Flexi Soft Gateways that allows a remote attacker to impact the availabiltiy of the gateways. CVSSv3 score of 7.5More info. Microsoft  Microsoft has updated Edge with the latest chromium updates and to fix Edge specific vuln...

0
  854 Hits

New Vulnerabilities Friday 05 May

Monthly Patches are out for MediaTek. New Alerts for Synology and Linux. MediaTek  MediaTek has published their Monthly Security Bulletin with details of vulnerabilities affecting MediaTek Smartphone, Tablet, AIoT, Smart display, Smart platform, OTT and TV chipsets. Seven vulnerabilities are rated High, And 19 vulnerabilities are rated Medium,...

0
  943 Hits

New Vulnerabilities Thursday 04 May

Fortinet has put out Monthly Patches. New Alerts for Cisco, OPC, and libssh. Cisco  A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow a remote attacker to execute arbitrary code on an affected device. CVSSv3 score of 9.8 Product is EOL, no updates will be provided.More info. OPC  A vul...

0
  802 Hits

New Vulnerabilities Wednesday 03 May

New Alerts for Google Chrome, Atos, F5, IBM, and Linux. Splunk Quarterly Patches have been pushed off 2 weeks. Google  Chrome for Desktop has been updated to correct 15 security vulnerabilities, most of which are rated Medium or Low.More info.Microsoft is aware. More info. Atos  Multiple vulnerabilities have been identified in Unify OpenS...

0
  1173 Hits

New Vulnerabilities Tuesday 02 May

Monthly Patches are out for Google Android, Google Pixel, and Samsung. New Alerts for Zyxel, Apple, and Linux. Apple has released their first ever Rapid Security Response, essentially just the patches.Splunk Quarterly Patches are expected this afternoon. Google  Android Monthly Patches are out, with 20 addressed vulnerabilities, 19 rated High ...

0
  806 Hits

New Vulnerabilities Monday 01 May

Qualcomm Monthly Patches are out. New Alerts for IBM, F5, and Linux. Monthly Patches for Google Android, Pixel, and Automotive, as well as MediaTek and Samsung are expected tomorrow.  Quarterly Patches for Splunk are expected tomorrow. Qualcomm  Monthly Patches are out for Qualcomm, with 9 addressed vulnerabilities, all rated High, plus o...

0
  1059 Hits

New Vulnerabilities Friday 28 April

New Alerts for Illumina, NetApp, and Linux. Illumina  Instruments with Illumina Universal Copy Service v2 are vulnerable due to binding to an unrestricted IP address. An unauthenticated malicious actor could use UCS to listen on all IP addresses, including those capable of accepting remote communications. Highest CVSSv3 score of 10More info. A...

0
  1030 Hits

New Vulnerabilities Thursday 27 April

New Alerts for Cisco, IBM, NetApp, and Dell. Cisco  A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. CVSSv3 score of 6.1More info. IBM  IBM App Connect Enterprise Certified ...

0
  973 Hits

New Vulnerabilities Wednesday 26 April

New Alerts for Keysight, Hitachi Energy, Tenable, and Linux. Keysight  Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid. A remote attacker could achieve RCE. CVSSv3 score of 9.8EOL, find a replacement.More info. Hitachi Energy  Multiple vulnerabilities i...

0
  1077 Hits

New Vulnerabilities Tuesday 25 April

New Alerts for Belden/Hirschmann, Microsoft Edge, IBM, and Linux. Belden  Hirschmann HiOS, Classic, HiSecOS, Wireless BAT-C2, Lite Managed, and Edge contain third-party software with vulnerabilities. Highest CVSSv3 score of 9.8More info. Microsoft  Microsoft has updated Edge with the latest chromium fixes.More info. IBM  IBM Db2 Grap...

0
  952 Hits

New Vulnerabilities Monday 24 April

Apparently it was a quiet weekend, I found no new vulnerabilities to report this morning.  Enjoy the great start to the week! Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar Page, ...

0
  740 Hits

New Vulnerabilities Friday 21 April

New Alerts for VMware and INEA. VMware  VMware Aria Operations for Logs contains several vulnerabilities, the worst of which allows a remote attacker to execute arbitrary code as root. Highest CVSSv3 score of 9.8More info. INEA  ME RTU contains an OS Command Injection vulnerability that could allow a remote attacker RCE. CVSSv3 score of 1...

0
  882 Hits

New Vulnerabilities Thursday 20 April

New Alerts for Cisco, PaperCut (Exploit), TIBCO, Microsoft Edge (Exploit), NetApp, and HCL Software.  Cisco  Cisco has published 6 new bulletins and 2 updated bulletins. Of the new bulletins, 2 are rated Critical, 2 rated High, and 2 rated Medium. Highest CVSSv3 score of 9.9More info. A vulnerability in the external authentication mechani...

0
  993 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/