2022年2月9日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Thedigitalcraft Atomcms:公開エクスプロイトまたは PoC が関連付けられました (SQL Injection)
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

悪用活動を確認

CVE-2022-24223 AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け

Thedigitalcraft Atomcms SQL Injection に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。

重大な露出リスク

CVE-2022-22536 SAP Multiple Products HTTP Request Smuggling

  • CVSS 10

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2021-39997 Huawei Emui Out-of-Bounds Write

  • CVSS 9.8

新たな重大 Huawei Emui Out-of-Bounds Write(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2021-39997 CVSS 9.8

There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this vulnerability may...

CVE-2022-22532 CVSS 9.8

In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49...

CVE-2022-22544 CVSS 9.1

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnost...

CVE-2022-22810 CVSS 9.8

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the...

CVE-2022-22813 CVSS 9.8

A CWE-798: Use of Hard-coded Credentials vulnerability exists.

CVE-2022-24310 CVSS 9.8

A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service...

CVE-2022-24311 CVSS 9.8

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing f...

CVE-2022-24312 CVSS 9.8

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing f...

CVE-2022-24313 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially lea...

Critical 公開を見る

cvelogic Threat Intelligence