Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 31 January

New Alerts for Dell, Hitachi, Trend Micro, and Linux. Dell  Dell has updated PowerFlex Appliance and PowerFlex Rack to fix multiple vulnerabilities in third-party components. Dell rates these Critical.More info. And here. Updates are available for Dell Unity, Dell UnityVSA, and Dell Unity XT to correct multiple security vulnerabilities that ma...

0
  1108 Hits

New Vulnerabilities Monday 30 January

New Alerts for IBM, QNAP, NetApp, and Linux. IBM  Multiple vulnerabilities were fixed in IBM Cloud Pak for Watson AIOps. Highest CVSSv3 score of 9.8More info. QNAP  A vulnerability has been reported to affect QNAP devices running QTS 5.0.1 and QuTS hero h5.0.1. If exploited, this vulnerability allows remote attackers to inject malicious c...

0
  951 Hits

New Vulnerabilities Friday 27 January

New Alerts for Rockwell Automation, Econolite, Microsoft PPTP, Microsoft Edge, IBM, and HCL Software. Rockwell Automation  Rockwell Automation is aware of multiple products that are affected by vulnerabilities in the GoAhead web server. Exploitation of these vulnerabilities could potentially have a high impact on the confidentiality, integrity...

0
  1000 Hits

New Vulnerabilities Thursday 26 January

New Alerts for ISC, Mitsubishi Electric, Tenable, and Linux.  ISC  ISC has published 4 new bulletins identifying DoS vulnerabilities in BIND 9. Highest CVSSv3 score of 7.5More info. Mitsubishi Electric  An authentication bypass vulnerability exists in the robot controller of industrial robot MELFA SD/SQ series and F-series. An attack...

0
  955 Hits

New Vulnerabilities Wednesday 25 January

New Alerts for VMware, Google Chrome, Apple, and Linux. VMware  Multiple vulnerabilities in VMware vRealize Log Insight could allow a remote attacker to collect sensitive information, achieve DoS, or perform RCE. Highest CVSSv3 score of 9.8More info. Google  Google has updated Chrome for Desktop to fix 6 security vulnerabilitiesm the most...

0
  888 Hits

New Vulnerabilities Tuesday 24 January

New Alerts for Crestron, Lexmark, Apple (Exploit), GE (Exploit), HCL Software, and Linux. Crestron  Crestron has patched the UC-engine product line for OpenSSL vulnerabilities. CVSSv3 score of 5.3More info. Lexmark  Lexmark has patched their printers to fix a vulnerability that allows an attacker to bypass protections on the device that p...

0
  963 Hits

New Vulnerabilities Monday 23 January

New Alerts for NetApp and Linux. NetApp  NetApp has published 9 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8 Only 1 bulletin includes patched software.More info. Linux  Mageia has updated the kernel and kernel firmware. More info. Security Wizardry Cyber Threat I...

0
  1081 Hits

New Vulnerabilities Friday 20 January

New Alerts for TP-Link, Medtronic, BD, PowerDNS, Microsoft and Linux. TP-Link  TP-Link router WR710N-V1-151022 and Archer-C5-V2-160201 are susceptible to two vulnerabilities, including a buffer overflow during HTTP Basic Authentication allowing a remote attacker to corrupt memory allocated on a heap causing DoS or RCE, and a side-channel attac...

0
  1176 Hits

New Vulnerabilities Thursday 19 January

New Alerts for Cisco, WithSecure, Mitel, and Wireshark. Cisco  A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. CVSSv3 score of 4.7More info. WithSecure  A DoS vulnera...

0
  1080 Hits

New Vulnerabilities Wednesday 18 January

New Alerts for GE Digital, IBM, D-Link, Mozilla, Git, and Apache. GE Digital  GE Digital Proficy Historian contains multiple vulnerabilities, including Authentication Bypass using an Alternate Path or Channel, Unrestricted Upload of File with Dangerous Type, Improper Access Control, and Weak Encoding for Password. Successful exploitation of th...

0
  1256 Hits

New Vulnerabilities Tuesday 17 January

Quarterly Patches for Oracle are out this afternoon. Pre-release notice is available. New Alerts for Mitsubishi Electric, IBM, and Linux. Mitsubishi Electric  An authorization bypass vulnerability exists in the WEB server function of the MELSEC iQ-F/iQ-R Series. An unauthenticated remote attacker may be able to access the WEB server function b...

1
  1419 Hits

New Vulnerabilities Monday 16 January

New Alerts for Xerox, Google ChromeOS, and Linux. Xerox  Xerox has updated Xerox WorkCentre models to correct vulnerabilities including insecure password encryption, show embedded system accounts, and remove the ability to disable functionality.More info. Google  Google has published a security update for ChromeOS / ChromeOS Flex.More inf...

0
  1075 Hits

New Vulnerabilities Friday 13 January

New Alerts for Sewio, InHand Networks, SAUTER, Microsoft Edge, IBM, NetApp, and Linux. Sewio  RTLS Studio contains multiple vulnerabilities, including Use of Hard-coded Password, OS Command Injection, Out-of-bounds Write, Cross-Site Request Forgery, Improper Input Validation, and Cross-site Scripting. Highest CVSSv3 score of 10.More info. InHa...

0
  1205 Hits

New Vulnerabilities Thursday 12 January

Quarterly Patches are out for Juniper Networks. New Alerts for Cisco, WAGO, IBM, Zyxel, and Linux. Cisco  Cisco has published 11 new bulletins, 1 Critical, 3 High, and the rest Medium. Highest CVSSv3 score of 9.0More info.Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Rout...

0
  1295 Hits

New Vulnerabilities Wednesday 11 January

New Alerts for Google Chrome, Moxa, Westermo, MAHO-PBX, NetApp, Western Digital, Black Box, and Linux. Google  Google has updated Chrome for Desktop to fix 17 security vulnerabilities.More info.Microsoft is aware. More info. Moxa  TN-4900 Series contains a Use of Hard-coded Credentials vulnerability that allows an attacker to gain privile...

0
  990 Hits

New Vulnerabilities Tuesday 10 January

Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for IBM, BD, and Linux. UPDATED TO ADD: Monthly Patches for Microsoft and Adobe are out now. Palo Alto Networks Monthly Patches are expected tomorrow. Microsoft  Microsoft Monthly Patches include 98 vulnerabilities, 11 rated Critical (7 of which allow RCE), 1 pub...

0
  1417 Hits

New Vulnerabilities Monday 09 January

New Alerts for IBM and Synology. IBM  Multiple security vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. Highest CVSSv3 score of 9.8More info. And here. Synology  A vulnerability allows remote attackers to possibl6 execute arbitrary commands via a susceptible version of Synology VPN Plus Server. CVSSv3 score of 10M...

1
  1051 Hits

New Vulnerabilities Friday 06 January

New Alerts for Digital Arts, HCL Software, and Linux.  Digital Arts  m-FILTER contains an improper authentication vulnerability when emails are being sent under certain conditions, and unintended emails may be sent by a remote attacker. CVSSv3 score of 5.3More info. And here. HCL Software  HCL Compass is affected by an IBM HTTP Serve...

0
  920 Hits

New Vulnerabilities Thursday 05 January

New Alerts for Dell, ManageEngine, and Linux.  Dell  PowerProtect DD remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system. Dell rates this CriticalMore info.Container Storage Modules remediation is available for a golang.org/x/net vulnerability that may b...

0
  1054 Hits

New Vulnerabilities Wednesday 04 January

Monthly Patches are out for Qualcomm, MediaTek, Google Android, Google Pixel, Samsung, and Fortinet. New Alerts for Dell and Apache Tomcat. Qualcomm  Monthly Patches for Qualcomm are out with 22 vulnerabilities, 3 rated Critical, 17 rated High, and 2 rated Medium. Highest CVSSv3 score of 9.3More info. MediaTek  Monthly Patches for MediaTe...

0
  931 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/