2022年10月18日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2022-33872 Fortinet Fortitester Command Injection

  • CVSS 9.8

新たな重大 Fortinet Fortitester Command Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2022-33874 Fortinet Fortitester Command Injection

  • CVSS 9.8

新たな重大 Fortinet Fortitester Command Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2022-39198 Apache Dubbo Code Execution

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Apache Dubbo Code Execution(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2022-31122 CVSS 9.8

Wire is an encrypted communication and collaboration platform.

CVE-2022-33872 CVSS 9.8

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login co...

CVE-2022-33874 CVSS 9.8

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login compo...

CVE-2022-39198 CVSS 9.8

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution.

CVE-2022-39428 CVSS 9.8

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).

CVE-2022-40684 CVSS 9.8

Fortinet Multiple Products Authentication Bypass

CVE-2022-40889 CVSS 9.8

Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

CVE-2022-41544 CVSS 9.8

GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-...

CVE-2022-43260 CVSS 9.8

Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.

Critical 公開を見る

cvelogic Threat Intelligence