2022年7月14日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 8 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2022-28373 Verizon Lvskihp Indoorunit Firmware RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Verizon Lvskihp Indoorunit Firmware RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2022-28375 Verizon Lvskihp Outdoorunit Firmware RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Verizon Lvskihp Outdoorunit Firmware RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2022-30113 Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.

  • CVSS 9.8

新たな重大 Fahou100 Electronic Mall System SQL Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2022-25800 CVSS 9.1

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

CVE-2022-25801 CVSS 9.1

Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

CVE-2022-28369 CVSS 9.8

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub...

CVE-2022-28373 CVSS 9.8

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition fu...

CVE-2022-28375 CVSS 9.8

Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofil...

CVE-2022-30113 CVSS 9.8

Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.

CVE-2022-32409 CVSS 9.8

A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows a...

CVE-2022-32417 CVSS 9.8

PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

Critical 公開を見る

cvelogic Threat Intelligence