2023年6月30日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2023-22814 Westerndigital My Cloud Os Auth Bypass

  • CVSS 10
  • 認証バイパス — 未認証アクセスのリスク

新たな重大 Westerndigital My Cloud Os Auth Bypass(CVSS 10)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2023-28323 Ivanti Endpoint Manager Deserialization

  • CVSS 9.8

新たな重大 Ivanti Endpoint Manager Deserialization(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2023-28324 Ivanti Endpoint Manager RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Ivanti Endpoint Manager RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2023-22814 CVSS 10

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to ca...

CVE-2023-28323 CVSS 9.8

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights.

CVE-2023-28324 CVSS 9.8

A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remot...

CVE-2023-28365 CVSS 9.1

A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows applicatio...

CVE-2023-31543 CVSS 9.8

A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to th...

UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB.

CVE-2023-3490 CVSS 9.8

SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.

CVE-2023-36812 CVSS 9.8

OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB).

CVE-2023-37303 CVSS 9.8

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.

Critical 公開を見る

cvelogic Threat Intelligence