Search
Close this search box.

Vulnerability Pulse

Every week, we catalog the major industrial cybersecurity vulnerabilities and updates you should know about. Here are the notable threats from the week of January 2 - 8. Sign up to get these updates right to your inbox!

JANUARY 05, 2022

VMware

VMware released a security advisory due to a vulnerability in Workstation, Fusion and ESXi that could be used to take control of affected systems.

Sources: VMware, CISA

Google

Google released Chrome version 97.0.4692.71 for Windows, Mac and Linux due to vulnerabilities that could lead to an attacker taking control of affected systems.

Sources: Google Chrome, CISA

SonicWall

SonicOS SessionID HTTP response header has a stack-based buffer overflow, which could lead to code execution in the firewall.

Sources: SonicWall, NIST

IBM

Versions of IBM PowerVM Hypervisor are vulnerable to a violation of the isolation between peer VMs.

Sources: IBM, IBM Support, NIST

JANUARY 04, 2022

StarWind

StarWind SAN & NAS build 1578 and StarWind Command Center Build 6864 Update Manager have a vulnerability that could lead to an escalation of privileges.

Sources: StarWind, NIST

Modem EMM

Modem EMM has a vulnerability that could lead to remote information disclosure.

Sources: MediaTek, NIST

Fortinet

Versions of FortiOS contain a vulnerability that could lead to an attacker gaining arbitrary files.


Sources: FortiGuard Labs, NIST

Apache

Versions of Apache Geode are vulnerable to a log file redaction of sensitive information flaw.

Sources: Apache, NIST

JANUARY 03, 2022

Atlassian

Versions of Atlassian Jira Server and Data Center are vulnerable to cross-site scripting.

Sources: Atlassian, NIST

Huawei Technologies

MyHuawei-App has a vulnerability that could compromise confidentiality.

Sources: HarmonyOS, NIST

SUBSCRIBE

GET ON THE BEAT

 

Keep your finger on the pulse of top industry news

RECENT NEWS
HACKS & ATTACKS
RESOURCES