2023年1月30日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2022-32522 Schneider-electric Interactive Graphical Scada System RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Schneider-electric Interactive Graphical Scada System RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2022-32523 Schneider-electric Interactive Graphical Scada System RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Schneider-electric Interactive Graphical Scada System RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2022-32524 Schneider-electric Interactive Graphical Scada System RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Schneider-electric Interactive Graphical Scada System RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2022-32513 CVSS 9.8

A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker b...

CVE-2022-32514 CVSS 9.8

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a we...

CVE-2022-32522 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially le...

CVE-2022-32523 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially le...

CVE-2022-32524 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially le...

CVE-2022-32525 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially le...

CVE-2022-32526 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially le...

CVE-2022-32527 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially le...

CVE-2022-32529 CVSS 9.8

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially le...

CVE-2022-48175 CVSS 9.8

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=d...

Critical 公開を見る

cvelogic Threat Intelligence