2021年5月25日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2021-25944 Deep-defaults Project Deep-defaults RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Deep-defaults Project Deep-defaults RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2021-25946 Nconf-toml Project Nconf-toml RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Nconf-toml Project Nconf-toml RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2021-30193 CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

  • CVSS 9.8

新たな重大 Codesys 750-8202 Firmware Out-of-Bounds Write(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2021-21658 CVSS 9.1

Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVE-2021-25944 CVSS 9.8

Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may le...

CVE-2021-25946 CVSS 9.8

Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may le...

CVE-2021-30190 CVSS 9.8

CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.

CVE-2021-30192 CVSS 9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.

CVE-2021-30193 CVSS 9.8

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

CVE-2021-30194 CVSS 9.1

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

CVE-2021-33574 CVSS 9.8

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free.

CVE-2021-33575 CVSS 9.8

The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of u...

Critical 公開を見る

cvelogic Threat Intelligence