Skip to main content

CND News and Blog

New Vulnerabilities Monday 16 October

New Alerts for BD, Rockwell Automation, Microsoft Edge, Dell, NetApp, and Linux. Oracle Quarterly Patch Update comes out tomorrow.  The pre-release announcement is available here. BD  BD has published third-party software security updates for Pyxis, Identity Provider Manager, Alaris, Care Coordination Engine, and Data Agent.More info. Roc...

0
  785 Hits

New Vulnerabilities Friday 13 October

New Alerts for BD, HP, NetApp, Node.js, Yifan (0-Day), and Linux. BD  BD has published third-party software security updates for ViperLT.More info. HP  A security vulnerability has been identified in the HP ThinUpdate utility which may lead to information disclosure. CVSSv3 score of 4.8More info. NetApp  NetApp has published a bullet...

0
  1254 Hits

New Vulnerabilities Thursday 12 October

Monthly Patches are out for Juniper Networks. New Alerts for Advantech, Mitsubishi Electric, Weintek, Pilz, SICK, IBM, Dell, Apache Tomcat, and Linux. Advantech  Advantech WebAccess contains an Information Exposure vulnerability that allows a remote attacker to access user credentials. CVSSv3 score of 6.5More info Mitsubishi Electric  Inf...

0
  1056 Hits

New Vulnerabilities Wednesday 11 October

Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Apple, Citrix, Google Chrome, HTTP/2 (Exploits), Samba, cURL, and Linux. Microsoft Exploit Microsoft Monthly Patches include 103 fixes, 12 are rated Critical and 3 are actively exploited. One is a fix for the HTTP/2 Rapid Reset DDoS vulnerability. Highest CVSSv3 score of 9.8...

0
  960 Hits

New Vulnerabilities Tuesday 10 October

Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for F5, Extreme Networks, and Linux. Monthly Patches for Microsoft and Adobe are expected later today. Siemens  Siemens has published 23 bulletins in their Monthly Patches, 12 new and 11 updated. Highest CVSSv3 score of 9.8More info.The CPCI85 firmware of SICAM A8000 ...

0
  869 Hits

New Vulnerabilities Monday 09 October

New Alerts for QNAP, NetApp, Microsoft PC Manager, and Linux. QNAP  Multiple vulnerabilities in ClamAV have been fixed in QTS, QuTS hero, and QuTScloud.More info. NetApp  NetApp has published 15 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 10.There are patches for fi...

0
  877 Hits

New Vulnerabilities Friday 06 October

New Alerts for Sophos (Exploit), IBM, and Linux. Sophos Exploit Sophos Firewall and SG UTM are vulnerable to at least one of the recent CVEs for Exim. Patches for Firewall are available, SG UTM are coming end of next week. Highest CVSSv3 score of 7.5 for the CVEs that are vulnerable.More info. IBM  IBM Security Verify Governance has been updat...

0
  914 Hits

New Vulnerabilities Thursday 05 October

New Alerts for Apple (Exploit), Cisco, Atos, Google, Microsoft (Exploit), Atlassian (Exploit), HP, Wireshark, and Linux  Apple Exploit Apple has published updates for actively exploited vulnerabilties in iOS and iPadOS. CVSSv3 score of 8.8More info. And here. Cisco  A vulnerability in Cisco Emergency Responder could allow a remote attacke...

0
  841 Hits

New Vulnerabilities Wednesday 04 October

New Alerts for SICK, Samsung, and Google Chrome.  SICK  SICK SIM1012 has all Ethernet ports are open by factory default. This could potentially allow a remote attacker to impact the availability, confidentiality, and integrity of the SICK SIM1012. CVSSv3 score of 9.8Remediation only, close the ports.More info.Multiple SICK products includ...

0
  796 Hits

New Alerts for Tuesday 03 October

Monthly Patches are out for MediaTek and Google Android. New Alerts for IBM and Linux. MediaTek  MediaTek has published their Monthly Patches with 3 vulnerabilities rated High, 9 rated Medium.More info. Google  Google Monthly Patches for Android are out, with 1 Critical vulnerability, and 31 High, with Arm, MediaTek, Unisoc, and Qualcomm ...

0
  864 Hits

New Vulnerabilities Monday 02 October

Monthly Patches are out for Qualcomm. New Alerts for Exim (0-Day), BD, Microsoft Edge (Exploit), and NetApp. Exim 0-Day A vulnerability in Exim allows remote attackers to execute arbitrary code on affected installations of Exim. CVSSv3 score of 9.8This was released as a 0-day.More info. And here. BD  BD has published security updates for Phoen...

0
  935 Hits

New Vulnerabilities Friday 29 September

New Alerts for Progress Software, Dell, and Linux. Progress Software  Vulnerabilities in the WS_FTP Server Ad hoc Transfer Module and in the WS_FTP Server manager interface have been identified. Highest CVSSv3 score of 10.More info. Dell  Dell Container Storage Modules remediation is available for multiple security vulnerabilities that co...

0
  1031 Hits

New Vulnerabilities Thursday 28 September

New Alerts for Cisco, Google Chrome (Exploit), IBM, HPE, and Mozilla (Exploit). Cisco  Cisco has published 15 new bulletins, 1 rated Critical, 7 rated High, and 7 rated Medium. Highest CVSSv3 score of 9.8More info.Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager could allow an attacker to access an affected instance or cause a DoS on ...

0
  832 Hits

New Vulnerabilities Wednesday 27 September

New Alerts for Baker Hughes, Squid, Apple, Belden, Juniper Networks (Exploit), Mozilla, and Linux. Baker Hughes  Bently Nevada 3500 Rack (TDI Firmware) contains several vulnerabilities including exposure of sensitive information, cleartext transmission of sensitive information, and authentication bypass by capture-replay. Highest CVSSv3 score ...

0
  935 Hits

New Vulnerabilities Tuesday 26 September

New Alerts for Hitachi Energy, IBM, Dell, and Linux. Hitachi Energy  Hitachi Energy includes libexpat open-source software in their AFx series products. There are multiple vulnerabilities in the libexpat component that allow a remote attacker to compromise the targeted devices availability, integrity, and confidentiality. Highest CVSSv3 score ...

0
  791 Hits

New Vulnerabilities Monday 25 September

New Alerts for WAGO, BD, Elasticsearch, and Linux. WAGO  WAGO products e!COCKPIT and WAGO-I/O-Pro both include vulnerable WIBU Systems Codemeter product. Highest CVSSv3 of 9.8More info. BD  BD has published Microsoft and third-party software updates for FACSCanto 10-Color System, FACSCelesta, FACSAria, FACSCanto II System, LSRFortessa, Fo...

0
  966 Hits

New Vulnerabilities Friday 22 September

New Alerts for Apple (Exploit), Real Time Automation (Exploit), D-Link (Exploit), QNAP, NetApp, and Linux.  Apple Exploit Apple has updated iOS, iPadOS, watchOS, macOS, and Safari to fix Exploited, Critical vulnerabilities.More info. Real Time Automation Exploit Real Time Automation 460MCBS contains a Cross-site Scripting vulnerability that co...

0
  799 Hits

New Vulnerabilities Thursday 21 September

New Alerts for Ingeteam, Frauscher Sensortechnik, Dell, Rockwell Automation, and Linux. Ingeteam  Three vulnerabilities have been identified in Ingeteam INGEPAC DA 3451 and INGEPAC EF MD. Highest CVSSv3 score of 8.6More info. Frauscher Sensortechnik  Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi are prone to multiple vulnerabilities ...

0
  875 Hits

New Vulnerabilities Wednesday 20 September

New Alerts for Omron, Atlassian, BIND, and Linux. Omron  Omron CJ/CS/CP series programmable logic controllers use the FINS protocol, which is vulnerable to brute-force attacks. The controllers do not enforce any rate limit on password guesses to password-protected memory regions. CVSSv3 score of 7.5More info. Atlassian  Four high-severity...

0
  999 Hits

New Vulnerabilities Tuesday 19 September

Updates for Phoenix Contact, Google Pixel, IBM, Apple, and Linux. Phoenix Contact  Multiple products are affected by WIBU Codemeter vulnerabilities. Highest CVSSv3 score of 10.More here. Google  Google updates for Pixel include Android security patches and 1 Pixel-specific security vulnerability rated High, currently being exploited.More ...

0
  814 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/