2022年5月5日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2022-24884 ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify).

  • CVSS 10

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2022-24817 Flux2 is an open and extensible continuous delivery solution for Kubernetes.

  • CVSS 9.9
  • 管理者/root への権限昇格の可能性

新たな重大 Fluxcd Flux2 Privilege Escalation(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2022-24877 Flux is an open and extensible continuous delivery solution for Kubernetes.

  • CVSS 9.9

新たな重大 Fluxcd Flux2 Path Traversal(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2022-24817 CVSS 9.9

Flux2 is an open and extensible continuous delivery solution for Kubernetes.

CVE-2022-24877 CVSS 9.9

Flux is an open and extensible continuous delivery solution for Kubernetes.

CVE-2022-24884 CVSS 10

ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify).

CVE-2022-27360 CVSS 9.8

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

CVE-2022-27411 CVSS 9.8

TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Ma...

CVE-2022-28582 CVSS 9.8

It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024)...

CVE-2022-28583 CVSS 9.8

It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) ro...

CVE-2022-28584 CVSS 9.8

It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024)...

CVE-2022-29176 CVSS 9.9

Rubygems is a package registry used to supply software for the Ruby language ecosystem.

CVE-2022-29535 CVSS 9.8

Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

Critical 公開を見る

cvelogic Threat Intelligence