CND News and Blog

New Vulnerabilities Tuesday 27 December
michele654
Vulnerabilities
There are no new vulnerabilities to report. (Creating the blog just to document I actually did do the work. )  ;) Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar Page, providing vu...
New Vulnerabilities Monday 26 December
michele654
Vulnerabilities
New Alert for Linux.  Linux  SUSE has updated the kernel. More info.OpenSUSE has updated the kernel. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar Page, providing...
New Vulnerabilities Friday 23 December
michele654
Vulnerabilities
New Alerts for Priva, BD, IBM, Dell NetApp, and Juniper. Priva  Priva TopControl Suite is vulnerable to secure shell (SSH) credentials being deciphered. An attacker could calculate the login credentials for the Priva product and login remotely. CVSSv3 score of 7.5More info. BD  BD has updated CCE, IDM, Data Agent, ViperLT, and Totalys for...
New Vulnerabilities Thursday 22 December
michele654
Vulnerabilities
New Alerts for Synology, Mitsubishi Electric, Hikvision, IBM, and Western Digital. Synology  Multiple vulnerabilities allow remote attackers to execute arbitrary command, conduct denial-of-service attacks or read arbitrary files via a susceptible version of Synology Router Manager (SRM). CERT Bund rates this CVSSv3 score of 10.More info. Mitsu...
New Vulnerabilities Wednesday 21 December
michele654
Vulnerabilities
New Alerts for D-Link, Dell, NetApp, Zyxel, curl, Open vSwitch, and Linux. D-Link  D-Link DIR-824/EE hardware contains several unauthenticated OS command injection vulnerabilities. Highest CVSSv3 score of 9.8More info. Dell  Dell SRM and Dell Storage Monitoring and Reporting have a security update for multiple third-party xomponent vulner...
New Vulnerabilities Tuesday 20 December
michele654
Vulnerabilities
New Alerts for Tenable, NVIDIA, Symantec, HCL Software, and Linux. Tenable  Nessus Network Monitor leverages third-party components, two of which were found to contain vulnerabilities. Highest CVSSv3 score of 9.8More info. NVIDIA  NVIDIA DGX A100 server and NVIDIA DGX Station A100 has been updated to address issues that may lead to code e...
New Vulnerabilities Monday 19 December
michele654
Vulnerabilities
New Alerts for BD, Microsoft Edge, IBM, HCL Software, and Linux. BD  BD has updated several products to apply Microsoft and third-party patches.More info. Microsoft  Microsoft has updated Edge to include the latest chromium-based security patches.More info. IBM  IBM Cognos Analytics has addressed multiple vulnerabilities. Highest CVS...
New Vulnerabilities Friday 16 December
michele654
Vulnerabilities
New Alerts for VMware, NetApp, Shibboleth, Samba, and Tenable. VMware  vRealize Network Insight (vRNI) contain command injection and directory traversal vulnerabilities present in the vRNI REST API. A remote attacker can execute commands and read arbitrary files. Highest CVSSv3 score of 9.8More info. VMware Workspace ONE Access and Identity Ma...
New Vulnerabilities Thursday 15 December
michele654
Vulnerabilities
New Alerts for Weidmueller, Rockwell Automation, IBM, Google (ChromeOS LTS), and Linux. Weidmueller  Multiple IoT and control products are affected by a JavaScript injection vulnerability in the XML editing system SCHEMA ST4 online help by Quanos Solutions GmbH. CVSSv3 score of 6.1More info. And here. Rockwell Automation  Rockwell Automat...
New Vulnerabilities Wednesday 14 December
michele654
Vulnerabilities
Monthly Patches are out for Microsoft (Exploit) and Adobe. New Alerts for Apple (Exploit), Contec, Google Chrome, Rockwell Automation, Dell, NETGEAR, and Mozilla. Palo Alto Networks Monthly Patches are expected out this afternoon. Microsoft Exploit Microsoft Monthly Patches include 74 vulnerabilities, 7 are Critical, 1 was previously disclosed, and...
New Vulnerabilities Wednesday 13 December
michele654
Vulnerabilities
Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Fortinet (Exploit), Citrix (Exploit), Hitachi Energy, Phoenix Contact, IBM, Hitachi, and Linux.            Monthly Patches for Microsoft and Adobe are expected this afternoon, Palo Alto Networks is expected tomorro...
New Vulnerabilities Monday 12 December
michele654
Vulnerabilities
New Alerts for IFM Electronic, IBM, NetApp, and Linux. IFM Electronic  Moneo Appliances contain a vulnerability where a remote attacker could reset the administrator's password with information from the default, self-signed certificate. CVSSv3 score of 9.8More info. IBM  Multiple vulnerabilities in the Expat library affect IBM Db2 Net Sea...
New Vulnerabilities Friday 09 December
michele654
Vulnerabilities
New Alerts for Aveva, Advantech, Dell, and WithSecure. Aveva  InTouch Access Anywhere contains a Relative Path Traversal that could allow a remote attacker with network access to read files on the system outside of the secure gateway web server. CVSSv3 score of 7.5More info. Advantech  Advantech iView contains a SQL Injection vulnerabilit...
New Vulnerabilities Thursday 08 December
michele654
Vulnerabilities
Monthly Patches are out for Fortinet. New Alerts for TIBCO, Rockwell Automation, Lenovo, PHP, and Wireshark. TIBCO  TIBCO Nimbus Web Client contains a vulnerability that allows an unauthenticated attacker with network access to exploit an open redirect on the affected system. CVSSv3 score of 9.3More info. Rockwell Automation  Logix Contro...
New Vulnerabilities Wednesday 07 December
michele654
Vulnerabilities
New Alerts for Cacti, F5, and Linux. Cacti  A command injection vulnerability allows a remote attacker to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. CVSSv3 score of 9.8More info. F5  BIG-IP and BIG-IQ are vulnerable to an issue in Java SE that could allow an attacker ...
New Vulnerabilities Tuesday 06 December
michele654
Vulnerabilities
Monthly Patches are out for Google Android, Google Pixel, and Samsung. New Alerts for Intel, Microsoft Edge (Exploit), IBM, and Dell. Intel Potential security vulnerabilities in some Intel Server Board Baseboard Management Controller (BMC) firmware may allow escalation of privilege or information disclosure. Highest CVSSv3 score of 8.3More info. Go...

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/

Are You Ready To Find Out More?

Arrange a Chat With Our Friendly Service Delivery Team.