2023年7月6日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Oretnom23 Lost And Found Information System:公開エクスプロイトまたは PoC が関連付けられました (SQL Injection)
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

悪用活動を確認

CVE-2023-33145 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け

Microsoft Edge Chromium Info Disclosure に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。

悪用活動を確認

CVE-2023-33592 Oretnom23 Lost And Found Information System SQL Injection

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け

Oretnom23 Lost And Found Information System SQL Injection に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。

重大な露出リスク

CVE-2023-36460 Mastodon is a free, open-source social network server based on ActivityPub.

  • CVSS 9.9

新たな重大 Joinmastodon Mastodon DoS(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=sy...

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2023-29381 CVSS 9.8

An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive informatio...

CVE-2023-29382 CVSS 9.8

An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.

CVE-2023-29824 CVSS 9.8

A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0.

CVE-2023-30319 CVSS 9.6

Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad5...

Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad...

Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710...

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS)

CVE-2023-35987 CVSS 9.8

PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.

CVE-2023-36459 CVSS 9.3

Mastodon is a free, open-source social network server based on ActivityPub.

CVE-2023-36460 CVSS 9.9

Mastodon is a free, open-source social network server based on ActivityPub.

Critical 公開を見る

cvelogic Threat Intelligence