2023年8月22日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Ivanti Sentry が CISA KEV に新規掲載 — 実環境での悪用を確認。
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

実際の悪用を確認

CVE-2023-38035 Ivanti Sentry Authentication Bypass

  • 実環境での悪用(CISA KEV)
  • CISA KEV に掲載
  • 認証バイパス — 未認証アクセスのリスク

Ivanti Sentry Auth Bypass は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。

重大な露出リスク

CVE-2022-36648 Qemu

  • CVSS 10

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2021-33388 dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y

  • CVSS 9.8

新たな重大 Dpic Project Dpic Buffer Overflow(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2020-24113 CVSS 9.1

Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitiv...

CVE-2021-33388 CVSS 9.8

dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y

CVE-2021-33390 CVSS 9.8

dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y.

CVE-2022-36648 CVSS 10

The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attacke...

CVE-2022-45611 CVSS 9.8

An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user logi...

CVE-2022-48174 CVSS 9.8

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35.

CVE-2022-48522 CVSS 9.8

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege esca...

CVE-2022-48565 CVSS 9.8

An XML External Entity (XXE) issue was discovered in Python through 3.9.1.

CVE-2023-36281 CVSS 9.8

An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt.

CVE-2023-4404 CVSS 9.8

The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 du...

Critical 公開を見る

cvelogic Threat Intelligence