Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 22 November

New Alerts for Zyxel and Linux. Zyxel  A flaw in the LTE3301-M209 firmware could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled. CVSSv3 score of 9.8More info. Linux  SUSE has updated grub2, binutils, and others. More info.OpenSUSE has updated gru...

0
  569 Hits
  0 Comments

New Vulnerabilities Monday 21 November

New Alerts for BD, Xerox, NetApp, and Linux. BD  BD is aware of and currently monitoring a vulnerability affecting all versions of Fortinet FortiOS products in use by BD Kiestra. CVSSv3 score of 9.6BD has not seen any exploits, but Fortinet reports this is actively exploited. The Fortinet bulletin was published 10 Oct 2022.More info. And here....

0
  617 Hits
  0 Comments

New Vulnerabilities Friday 18 November

New Alerts for Red Lion Controls and Linux. Red Lion Controls  Red Lion Controls Crimson is vulnerable to path traversal. When attempting to open a file using a specific path, the user's password hash is sent to an arbitrary host. This could allow an attacker to obtain user credential hashes. CVSSv3 score of 7.5More info. Linux  SUSE has ...

0
  524 Hits
  0 Comments

New Vulnerabilities Thursday 17 November

New Alerts for BD, IBM, and Linux. BD  BD has published security bulletins for updates to Microsoft and third-party software in Identity Provider Manager, Alaris, Pyxis, and Data Agent products.More info. IBM  A command injection vulnerability in IBM InfoSphere DataStage was addressed. CVSSv3 score of 9.8More info. Linux  Ubuntu has ...

0
  669 Hits
  0 Comments

New Vulnerabilities Wednesday 16 November

New Alerts for Mozilla, BD, and Linux. Mozilla  Mozilla has published security bulletins for Firefox, Firefox ESR, and Thunderbird, all rated High. Highest CVSSv3 score of 8.1More info. BD  BD has published security bulletins for updates to Microsoft and third-party software in FACSAria, FACS Sample Prep Assistant Systems, FACSLyric, Pyxi...

0
  543 Hits
  0 Comments

New Vulnerabilities Tuesday 15 November

New Alerts for Phoenix Contact, Mitsubishi Electric, Moxa, Google ChromeOS, and Linux. Phoenix Contact  A denial of service of the HTTPS management interface of FL MGUARD and TC MGUARD devices can be triggered by a larger number of unauthenticated HTTPS connections, incoming from different source IPs. CVSSv3 score of 7.5More info. And here. Mi...

0
  570 Hits
  0 Comments

New Vulnerabilities Monday 14 November

New Alerts for IBM and Linux. A welcome quiet after a busy couple of weeks. IBM  A command injection vulnerability in IBM InfoSphere DataStage was addressed. CVSSv3 score of 9.8More info. Linux  Alpine Linux has released version 3.16.3. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry....

0
  520 Hits
  0 Comments

New Vulnerabilities Friday 11 November

New Alerts for Omron, Moxa, Belden, Microsoft Edge, Dell, NetApp, and Linux. Omron  An Active Debug Code vulnerability exists in the NJ/NX-series Machine Automation Controllers. A remote attacker can illegally access the controllers and use the vulnerability to cause a DoS or RCE. CVSSv3 score of 8.3More info. And here.Use of Hard-coded Creden...

0
  436 Hits
  0 Comments

New Vulnerabilities Thursday 10 November

New Alerts for Apple, IBM, Cisco, Hitachi, Tenable, and Linux. Apple  Apple has published updates for iOS, iPadOS, and macOS Ventura that fixes vulnerabilities in libxml2.More info. And here. And here. IBM  IBM QRadar Network Packet Capture, IBM QRadar Assistant app for IBM QRadar SIEM, IBM Cloud Pak for Security, includes components with...

1
  752 Hits
  0 Comments

New Vulnerabilities Wednesday 09 November

Monthly Patches are out for Microsoft. New Alerts for Intel, Citrix, VMware, Google Chrome, Veeam, Brocade, and Linux.        Adobe had no Monthly Patches this cycle.     Palo Alto Network Monthly Patches should be out this afternoon. Microsoft Exploit Monthly Patches are out, with 68 vulnerabilitie...

0
  590 Hits
  0 Comments

New Vulnerabilities Tuesday 08 November

Monthly Patches are out for Siemens, Schneider Electric, Qualcomm, Google Android, Google Pixel, Samsung, and SAP. New Alerts for NETGEAR and Linux.       This afternoon Microsoft and Adobe Monthly Patches should be out.  Tomorrow is Palo Alto Networks. Schneider Electric  Monthly Patches are out, with 1 new bulletin a...

0
  626 Hits
  0 Comments

New Vulnerabilities Monday 07 November

Monthly Product Security Bulletin is out for Mediatek. New Alerts for Wiesemann & Theis, NetApp, and NETGEAR.   Because last week's Tuesday was the 1st, and Qualcomm publishes their monthly bulletin on the first Monday, Tomorrow is Monthly Patch Day for 8 vendors, including Qualcomm, Google Android, Samsung, Microsoft, Adobe, SAP, Siemens,...

0
  618 Hits
  0 Comments

New Vulnerabilities Friday 04 November

New Alerts for ETIC Telecom, Tenable, IBM, Dell, VMware, and Linux. ETIC Telecom  ETIC Telecom Remote Access Server contains several vulnerabilities, including Insufficient Verification of Data Authenticity, Path Traversal, and Unrestricted Upload of File with Dangerous Type. Successful exploitation of these vulnerabilities could allow an atta...

0
  768 Hits
  0 Comments

New Vulnerabilities Thursday 03 November

Quarterly Patches are out for Splunk. New Alerts for Cisco, CODESYS, SICK, IBM, PHP, and HCL Software. Cisco  Cisco has published 11 new bulletins, 4 rated High and 7 rated Medium. Highest CVSSv3 score of 8.8More info. A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attac...

0
  744 Hits
  0 Comments

New Vulnerabilities Wednesday 02 November

Monthly Patches are out for Fortinet. New Alerts for OpenSSL, Dell, Google LTS ChromeOS, and Linux.      Splunk Quarterly Patches were pushed to today. OpenSSL  OpenSSL released version 3.0.7, which patches two related vulnerabilities rated as High. Although originally rated Critical, it was determined the complexity to exploit ...

0
  627 Hits
  0 Comments

New Vulnerabilities Tuesday 01 November

New Alerts for Microsoft Edge (Exploit), Hitachi, ClamAV, VMware, Apache, Kaspersky, and Linux. Microsoft  Microsoft has updated Edge to include the latest chromium fix for an actively exploited vulnerability.More info. Hitachi  Hitachi has updated NetBackup in JP1/VERITAS. More info. ClamAV  ClamAV has updated to fix 3 vulnerabiliti...

0
  631 Hits
  0 Comments

New Vulnerabilities Monday 31 October

New Alerts for IBM, Dell, NetApp, and PHP. Tomorrow will see the release of the Critical OpenSSL 3.x update.  This affects so many products, watch for everyone to be updating for OpenSSL, while it begins to be exploited once details are released.  See the link below.Splunk Quarterly Patches are expected tomorrow as well. IBM  Multipl...

1
  632 Hits
  0 Comments

New Vulnerabilities Friday 28 October

New Alerts for Trihedral, Rockwell Automation, Google Chrome (Exploit), Microsoft Edge, Apple iOS (Exploit), Dell, and IBM. Trihedral  Trihedral VTScada contains an Improper Input Validation vulnerability that allows a remote attacker to cause a DoS. CVSSv3 score of 7.5.More info. Rockwell Automation  A vulnerability in FactoryTalk Alarms...

0
  779 Hits
  0 Comments

New Vulnerabilities Thursday 27 October

New Alerts for Dell, HP, Wireshark, Nessus, and Linux. Dell  Dell PowerStore Family remediation is available for multiple security vulnerabilities that could be exploited by remote attackers to compromise the affected system. Dell rates this Critical.More info. HP  Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Do...

0
  609 Hits
  0 Comments

New Vulnerabilities Wednesday 26 October

New Alerts for Google Chrome, VMware, IBM, Johnson Controls, Aruba, SICK, Haas Automation, Delta Electronics, HEIDENHAIN, curl, and Linux. GoogleGoogle has updated Chrome for Desktop with fixes for 14 security vulerabilities.More info. VMware  VMware Cloud Foundation has been updated to correct multiple vulnerabilities, including an RCE in XSt...

0
  920 Hits
  0 Comments

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/