2022年6月6日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 7 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2022-31481 Carrier Ep4502 Firmware

  • CVSS 10

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2022-1680 Gitlab

  • CVSS 9.9

新たな重大公開(CVSS 9.9)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2022-30927 Simple Task Scheduling System Project Simple Task Scheduling System SQL Injection

  • CVSS 9.8

新たな重大 Simple Task Scheduling System Project Simple Task Scheduling System SQL Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2022-1680 CVSS 9.9

An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions startin...

CVE-2022-30927 CVSS 9.8

A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application database.

CVE-2022-31479 CVSS 9.6

An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed durin...

CVE-2022-31481 CVSS 10

An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer.

CVE-2022-31483 CVSS 9.1

An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anyw...

CVE-2022-31768 CVSS 9.8

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection.

CVE-2022-32511 CVSS 9.8

jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

Critical 公開を見る

cvelogic Threat Intelligence