Alert Details

Computer Network Defence Alert State

 

Radar Page

The Computer Network Defence Alert State is designed to give a granular and more dynamic visualisation of the current security threat.  Increase in alert state will occur immediately upon detection of a new threat and drop again by one level each working day.  The rationale is that vulnerabilities often occur in clusters, therefore reducing the alert state again quickly, will increase your visibility of new threats to the same product.  It is important that the radar page is viewed at least daily in order to track these changes. Reductions in alert state occur at approximately 1900 GMT/UTC. Significant vulnerabilities may remain for longer. Vulnerabilities on this page are predominantly remotely executable, very few local server exploits will be shown.

 

Alert Definitions

NORMAL This alert state represents the normal level of security with minimal activity relating to the product.  The next stage above this level is 2, however falling alerts will go through 1 when returning to normal.

LOW This alert state indicates that an alert has been recognised for this product within the last few days but it is now returning to normal.  Inclusion of this level is for viewers that don't monitor this alert system regularly.

INCREASED This alert state indicates a need to increase the security posture due to an emerging threat for which there is currently no exploit, or you are witnessing the reduction in alert state after being at level 3 for more than 1 working day.

HIGH This alert state indicates a significant threat to the product, where exploits exist or where the vulnerability is potentially devastating.

PATCHES This alert state indicates that patches are available for vulnerabilities that had previously resulted in a need for the alert state to increase and subsequently fall. The level of 2 or 3 indicates the urgency to patch.

EXPLOIT This alert state indicates that exploit code is available for vulnerabilities that had previously resulted in a need for the alert state to increase and subsequently fall. The level of 2 or 3 indicates the threat of the exploit.

 

Current Alerts

 

AlertTitleCisco

Cisco has published updates for 12.1E version of IOS for a vulnerability originally published September 2011.

The Cisco IOS Software network address translation (NAT) feature contains multiple (DoS) vulnerabilities in the translation of the following protocols: NetMeeting Directory (Lightweight Directory Access Protocol, LDAP), Session Initiation Protocol. (Multiple vulnerabilities), H.323 protocol.

More info.

 

AlertTitleSCADA

There is a public report identifying an unallocated Unicode string vulnerability with proof-of-concept (PoC) exploit code that affects the Invensys Wonderware SuiteLink (SL) service (slssvc), which is part of the System Platform software suite. According to this report, the vulnerability allows an attacker to remotely crash older versions of the slssvc service by sending a long and unallocated Unicode string.

Invensys has provided directions for mitigation of this vulnerability, and will provide an upgrade path to unaffected versions of the software.

More info.

AlertTitleOSX

Apple has released an update for OS X.  This update disables Adobe Flash Player if it is older than 10.1.102.64 by moving its files to a new directory. This update presents the option to install an updated version of Flash Player from the Adobe website.

More info.

 

Also, Apple has released an update that runs a malware removal tool that will remove the most common variants of the Flashback malware.

More info.

AlertTitleCisco

Cisco ASA 5500 Series Adaptive Security Appliances (Cisco ASA) uses an ActiveX control on client systems to perform port forwarding operations.  A remote, unauthenticated attacker who could convince a user to connect to a malicious web page could exploit this issue to execute arbitrary code on the affected machine with the privileges of the web browser.  The affected ActiveX control is distributed to endpoint systems by Cisco ASA.  However, the impact of successful exploitation of this vulnerability is to the endpoint system only and does not compromise Cisco ASA devices.

More info.

AlertTitleAdobe

A vulnerability has been identified in Adobe Photoshop CS5, which can be exploited by malicious people to compromise a user's system.  Successful exploitation allows execution of arbitrary code, but requires tricking a user into opening a malicious file.

More info.

AlertTitleApple

Multiple vulnerabilities have been reported in QuickTime, which can be exploited by malicious people to compromise a user's system.

More info.

 

 

AlertTitleIBM

A vulnerability with unknown impact has been reported in IBM WebSphere Application Server for z/OS.

More info.

AlertTitleRealNetworks

RealPlayer contains vulnerabilities that may allow remote code execution.

More info.

AlertTitleHitachi

A vulnerability has been reported in Hitachi COBOL GUI Run Time System and Hitachi COBOL Server GUI Run Time System, which can be exploited by malicious people to compromise a user's system.
More info.

 

Also, Two vulnerabilities have been reported in Hitachi IT Operations Director, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service).

More info.

AlertTitleGoogle

Google has released an update for Chrome that corrects several security vulnerabilities.

More info.

 

 

 

 
 

 

Return to the top of the Alert Details Page

 

Go to the Radar Page                                                 cnd-logo-full-3

 

Useful Links

 

These are links our analysts and radar page patrons find useful.  If you would like to suggest a link for this section, please send your suggestions to This e-mail address is being protected from spambots. You need JavaScript enabled to view it

 

http://isc.sans.edu/
http://www.us-cert.gov/
http://www.auscert.org.au/
http://cve.mitre.org/
http://atlas.arbor.net/

http://www.cert.org/advisories/
http://secunia.com/Advisories
http://www.vupen.com/english/security-advisories/
http://www.securityfocus.com/vulnerabilities
http://www.coresecurity.com/content/corelabs-advisories
http://osvdb.org/



http://www.iss.net/threats/ThreatList.php
http://www.sourcefire.com/security-technologies/snort/vulnerability-research-team/advisories

 

Any other comments on our site or the Radar Page are welcome as well!

http://www.ubuntu.com/usn/usn-1215-1/
Copyright 2004 through 2011 Computer Network Defence, Ltd.
All rights reserved