Skip to main content

CND News and Blog

New Vulnerabilities Friday 02 June
michele654
Vulnerabilities
Quarterly Patches are out for Splunk. New Alerts for IBM, D-LINK, and STARFACE PBX. Splunk  Splunk patches are out with 15 bulletins, 1 rated Critical, 7 rated High, 6 rated Medium, and 1 rated Low. Highest CVSSv3 score of 9.8More info. IBM  IBM Edge Application Manager addresses a security vulnerability in Webpack. CVSSv3 score of 9.1Mor...
New Vulnerabilities Thursday 01 June
michele654
Vulnerabilities
New Alerts for Mitsubishi Electric, NetApp, and Linux. MoveIT Transfer has identified a Critical vulnerability that allows unauthorized access to the environment. Mitsubishi Electric  Multiple vulnerabilities exist in MELSEC iQ-R Series/iQ-F Series EtherNet/IP modules and EtherNet/IP configuration tools. Due to improper handling of the pa...
New Vulnerabilities Wednesday 31 May
michele654
Vulnerabilities
New Alerts for Google Chrome, VMware, IBM, Dell, and Linux. Google  Google has updated Chrome for Desktop to fix 16 security vulnerabilities, the most severe of which could allow for arbitrary code execution.More info. VMware  VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. CVSSv3 score ...
New Vulnerabilities Tuesday 30 May
michele654
Vulnerabilities
New Alerts for Belden and Hitachi. Belden  Multiple libexpat vulnerabilities exist in HiOS, Classic, HiSecOS, Wireless BAT-C2, Lite Managed, and Edge. Highest CVSSv3 score of 9.8More info.StrongSwan vulnerability exists in Eagle and OWL. CVSSv3 score of 7.5More info. Hitachi  Hitachi has published updates for JP1/Veritas and Cosminexus HT...
New Vulnerabilities Monday 29 May
michele654
Vulnerabilities
New Alerts for IBM, NetApp, and Linux. IBM  IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data is vulnerable to a heap-based buffer overflow in Perl. CVSSv3 score of 9.8More info.A vulnerability in Etcd-io could affect IBM CICS TX Standard. CVSSv3 score of 9.8More info. And here.IBM App Connect Enterprise Certified Container is vu...
New Vulnerabilities Friday 26 May
michele654
Vulnerabilities
New Alerts for BD, HPE, and NetApp. BD  BD has published third-party software updates for several products.More info. HPE  A security vulnerability in the OpenSSL Library impacts HPE IceWall products. The vulnerability could be exploited resulting in remote DoS. CVSSv3 score of 7.5More info. NetApp  NetApp Blue XP Connector exposes i...
New Vulnerabilities Thursday 25 May
michele654
Vulnerabilities
New Alerts for Zyxel and Wireshark. Zyxel  Zyxel has released patches for firewalls affected by multiple buffer overflow vulnerabilities. CVSSv3 score of 9.8More info. Wireshark  Wireshark has published 9 new bulletins identifying DoS vulnerabilities. CVSSv3 score of 6.5More info. Security Wizardry Cyber Threat Intelligence - The Radar Pa...
New Vulnerabilities Wednesday 24 May
michele654
Vulnerabilities
New Alerts for Netgate, Hitachi Energy, Bosch, GitLab, Dell, and Linux. Netgate  An IPv6 packet larger than the MTU on an interface can lead to a kernel panic in pf, resulting in a DoS.More info. Hitachi Energy  Multiple vulnerabilities in the libexpat affect the AFS65x, AFS66x, AFS67x, AFR67x and AFF66x series products. Highest CVSSv3 sc...
New Vulnerabilities Tuesday 23 May
michele654
Vulnerabilities
New Alerts for Mitsubishi Electric, Meinberg, IBM, Hitachi, Apache Tomcat, and Linux. Mitsubishi Electric  DoS and RCE vulnerabilities exists in the MELSEC Series CPU modules. A remote attacker may cause a DoS condition or execute malicious code on a target product by sending specially crafted packets. CVSSv3 score of 10.More info. Meinberg&nb...
New Vulnerabilities Monday 22 May
michele654
Vulnerabilities
All quiet so far, but it's early in the day. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industrie...
New Vulnerabilities Friday 19 May
michele654
Vulnerabilities
New Alerts for Johnson Controls, Carlo Gavazzi (exploit), Apple (exploit), Microsoft Edge, WithSecure, and Linux. Johnson Controls  A vulnerability impacting OpenBlue Enterprise Manager Data Collector allows a remote attacker to expose sensitive information. CVSSv3 score of 10More info. And here. Carlo Gavazzi Exploit Carlo Gavazzi Powersoft h...
New Vulnerabilities Thursday 18 May
michele654
Vulnerabilities
New Alerts for Cisco (Exploit), Mitsubishi Electric, IBM, Dell, Xerox, NetApp, and Aruba. Cisco Exploit Cisco has published 9 new bulletins and 1 updated bulletin. Of the new bulletins, 1 is rated Critical, the rest are Medium. Highest CVSSv3 score of 9.8More info.Multiple vulnerabilities in the web-based user interface of certain Cisco Small Busin...
New Vulnerabilities Wednesday 17 May
michele654
Vulnerabilities
New Alerts for Google Chrome, Snap One, WAGO, ZIBM, and Linux. Google  Google has published an update for Chrome for Desktop that includes 12 security fixes. At least 1 is rated Critical.More info.Microsoft is aware. More info. Snap One  OvrC Cloud, OvrC Pro Devices contain several vulnerabilities that allow a remote attacker to impersona...
New Vulnerabilities Tuesday 16 May
michele654
Vulnerabilities
New Alerts for SICK, IBM, Hitachi, vm2, and Linux. SICK  Multiple security vulnerabilities in the SICK FTMg device that could allow a remote attacker to impact the availabiltiy or confidentaility of the FTMg device. Highest CVSSv3 score of 7.5More info. IBM  IBM Edge Application Manager addresses security vulnerabilities in open source so...
New Vulnerabilities Monday 15 May
michele654
Vulnerabilities
New Alerts for OPC, IBM, Tenable, Vyper, and Linux. OPC  OPC has resolved a vulnerability in the OPC UA Legacy Java Stack that enables a remote attacker to block OPC UA server applications so that they can no longer serve client application. CVSSv3 score of 7.5More info. IBM  IBM Cloud Pak for Network Automation addresses multiple securit...
New Vulnerabilities Friday 12 May
michele654
Vulnerabilities
New Alerts for SDG Technologies, Rockwell Automation, Teltonika, IBM, Dell, and Netapp. SDG Technologies  The PnPSCADA system contains a critical unauthenticated error-based PostgreSQL Injection vulnerability allowing a remote attacker to engage with the underlying database seamlessly and passively. CVSSv3 score of 9.8No patch yet.More info. R...

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/