Skip to main content

CND News and Blog

New Vulnerabilities Monday 28 August

New Alerts for IBM, NetApp, Google ChromeOS, and Apache Tomcat. IBM  IBM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from systemd, libcap, openssl-libs, libxml2, go-toolset, and prometheus-operator. Highest CVSSv3 score of 9.8More info. NetApp  NetApp has published 2 new bulletins identifying ...

0
  1098 Hits

New Vulnerabilities Friday 25 August

New Alerts for Opto 22, KNX, D-Link, IBM, NetApp, and Linux. Opto 22  SNAP PAC S1 contains several vulnerabilities that could allow a remote attacker to brute force passwords, access certain device files, or cause a DoS. Highest CVSSv3 score of 7.5No patch, secure your network.More info. KNX  KNX devices that use KNX Connection Authorizat...

0
  869 Hits

New Vulnerabilities Thursday 24 August

New Alerts for Moxa, Sprecher Automation, Rockwell Automation, WithSecure, Wireshark, and Linux. Moxa  ioLogik 4000 Series is affected by multiple web server vulnerabilities and an improper access control vulnerability. Highest CVSSv3 score of 5.3More info. Sprecher Automation  A vulnerability in Wibu Systems CodeMeter User Runtime Softwa...

0
  1192 Hits

New Vulnerabilities Wednesday 23 August

New Alerts for Google Chrome, Ormazabal, Aruba, DrayTek, Mitel, and Linux. Google  Five security vulnerabilities have been fixed in Google Chrome, the most severe of which could allow for arbitrary code execution.More info. Ormazabal  Ten vulnerabilities have been identified in Ormazabal's ekorCCP and ekorRCI industrial devices. Highest C...

0
  935 Hits

New Vulnerabilities Tuesday 22 August

New Alert for Microsoft Edge. Microsoft  Microsoft has updated Edge with the latest chromium updates and an Edge-specific vulnerability fix. CVSSv3 score of 6.5 for the Edge vulnerability.More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The...

0
  793 Hits

New Vulnerabilities Monday 21 August

New Alerts for Rockwell Automation, Ivanti (Exploit), and Linux. Rockwell Automation  ThinManager contains 3 vulnerabilities that could allow a remote attacker to cause a DoS or delete arbitrary files. Highest CVSSv3 score of 9.8More info. Ivanti Exploit A vulnerability has been discovered in Ivanti Sentry that allows a remote attacker to acce...

0
  1020 Hits

New Vulnerabilities Friday 18 August

New Alerts for Walchem, Microsoft Edge, Juniper, Ubiquiti, Supermicro (Exploit), CODESYS, HPE, NetApp, and Linux. Walchem  Walchem Intuition 9 firmware is missing authentication for some of the API routes of the management web server, allowing a remote attacker to download and export sensitive data. CVSSv3 score of 7.5More info. Microsoft ...

0
  990 Hits

New Vulnerabilities Thursday 17 August

New Alerts for Cisco, ClamAV, Mitsubishi Electric, Moxa, Atlassian, IBM, and Synology. Cisco  Cisco has published 17 new bulletins, 5 rated High and 12 rated Medium. Highest CVSSv3 score of 8.1More info.Secure Endpoint products are affected by a ClamAV vulnerability allowing a DoS. CVSSv3 score of 7.5 More info. And here. ClamAV  ClamAV h...

0
  1201 Hits

New Vulnerabilities Wednesday 16 August

New Alerts for Google Chrome, BD, Meinberg, and Linux. Google  Google has published an update for Chrome for Desktop that includes 26 security fixes.More info.Microsoft is aware. More info. BD  BD has published security patches for Pyxis, Data Agent, CCE, Alaris, and IDM.More info. Meinberg  LANTIME firmware has been updated to inclu...

0
  959 Hits

New Vulnerabilities Tuesday 15 August

New Alerts for Zyxel, NetApp, and Linux. Zyxel  Zyxel has released updates for several switches to fix a DoS vulnerability.More info. NetApp  NetApp has published 9 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score of 9.8. No patches yet.More info. Linux  SUSE has updat...

0
  855 Hits

New Vulnerabilities Monday 14 August

New Alert for Linux. Linux  SUSE has updated the kernel and kernel firmware. More info.OpenSUSE has updated the kernel and kernel firmware. More info.Debian has updated the kernel and microcode. More info.Ubuntu has updated the kernel and microcode. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securityw...

0
  859 Hits

New Vulnerabilities Friday 11 August

New Alert for Belden. Happy Friday! Belden  Hirschmann Wireless OWL contains a vulnerability in zlib. CVSSv3 score of 9.8More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar ...

0
  1039 Hits

New Vulnerabilities Thursday 10 August

New Alerts for Xerox, Dell, Softing (0-Day), and Linux. Xerox  Xerox has updated FreeFlow Print Server with the latest 3rd-party software updates. Highest CVSSv3 score of 9.8More info. And here. Dell  Security Update for Dell ESI (Enterprise Storage Integrator) for SAP LAMA multiple security vulnerabilities. Dell rates this Critical.More ...

0
  858 Hits

New Vulnerabilities Wednesday 09 August

Monthly Patches are out for Microsoft and Adobe. New Alerts for Rockwell Automation, IBM, Dell, Hitachi, and Linux. Microsoft Exploit Microsoft Monthly Patches are out, with patches for 88 vulnerabilities, 6 are Critical, and 2 are being exploited. Highest CVSSv3 score of 9.8More info. And here. And here. Adobe  Adobe Monthly Patches include p...

0
  918 Hits

New Vulnerabilities Tuesday 08 August

Monthly Patches are out for Google Android, Google Pixel, Samsung, Siemens, Schneider Electric, and SAP. New Alerts for Microsoft Edge, Zoom, Phoenix Contact, and Linux.           Microsoft and Adobe Monthly Patches are expected this afternoon. Google  Google Android Monthly Patches are out, with 37 addressed vuln...

0
  926 Hits

New Vulnerabilities Monday 07 August

Monthly Patches are out for Qualcomm and MediaTek. New Alerts for Dell, NetApp, and Linux.        Tomorrow will be Patch Day for Google (Android/Pixel/Automotive OS), Samsung, Microsoft, Adobe, SAP, Siemens, and Schneider Electric. Qualcomm  Qualcomm Monthly Patches are out, with 13 vulnerabilities, 4 rated Critical, 6 rate...

0
  888 Hits

New Vulnerabilities Friday 04 August

New Alerts for TEL-STER, NetApp, WithSecure, Ivanti, and Linux. TEL-STER  External input could be used on TEL-STER TelWin SCADA WebInterface which could allow a remote attacker to read files on the system. CVSSv3 score of 7.5More info. NetApp  NetApp has published 11 new bulletins identifying vulnerabilities in third-party software includ...

0
  940 Hits

New Vulnerabilities Thursday 03 August

New Alerts for Cisco, Mitsubishi Electric, Google, Dell, Veritas, Mozilla, Tenable, and Linux. Cisco  Cisco has published 2 new bulletins, both rated Medium.More info.A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow a remote attacker to bypass a configured rule, allowing traffic onto ...

0
  1230 Hits

New Vulnerabilities Wednesday 02 August

New Alerts for APSystems, HPE, F5, Mozilla, GitLab, ZKTeco, and Linux. APSystems  OS command injection affects Altenergy Power Control software via shell metacharacters in the timezone parameter. CVSSv3 score of 9.8No response from vendor.More info. HPE  Potential security vulnerabilities has been identified in HPE Fabric OS. These vulner...

0
  1113 Hits

New Vulnerabilities Tuesday 01 August

New Alerts for Omron, IBM, Hitachi, NetApp, and Linux. Omron  Vulnerabilities related to NicheStack TCP/IP stack exist in the EtherNet/IPTM option board for Multi-function Compact Inverter 3G3MX2. An attacker may use these vulnerabilities to perform RCE, DoS, or obtain sensitive information. Highest CVSSv3 score of 9.8No patch.More info. IBM&n...

0
  1230 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/