2021年8月8日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2021-38190 An issue was discovered in the nalgebra crate before 0.27.1 for Rust.

  • CVSS 9.8

新たな重大 Dimforge Nalgebra Out-of-Bounds Write(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2021-38197 Go-unarr Project Go-unarr Directory Traversal

  • CVSS 9.8

新たな重大 Go-unarr Project Go-unarr Directory Traversal(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2020-36443 An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust.

  • CVSS 9.8

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2020-36443 CVSS 9.8

An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust.

CVE-2020-36452 CVSS 9.8

An issue was discovered in the array-tools crate before 0.3.2 for Rust.

CVE-2021-38187 CVSS 9.8

An issue was discovered in the anymap crate through 0.12.1 for Rust.

CVE-2021-38188 CVSS 9.8

An issue was discovered in the iced-x86 crate through 1.10.3 for Rust.

CVE-2021-38189 CVSS 9.8

An issue was discovered in the lettre crate before 0.9.6 for Rust.

CVE-2021-38190 CVSS 9.8

An issue was discovered in the nalgebra crate before 0.27.1 for Rust.

CVE-2021-38194 CVSS 9.8

An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust.

CVE-2021-38195 CVSS 9.8

An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust.

CVE-2021-38196 CVSS 9.8

An issue was discovered in the better-macro crate through 2021-07-22 for Rust.

CVE-2021-38197 CVSS 9.8

unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR archive.

Critical 公開を見る

cvelogic Threat Intelligence