2024年7月1日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2024-38366 trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.

  • CVSS 10

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2024-38513 Gofiber Fiber

  • CVSS 10

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2024-39251 An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2....

  • CVSS 10
  • 管理者/root への権限昇格の可能性

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2024-28200 CVSS 9.1

The N-central server is vulnerable to an authentication bypass of the user interface.

CVE-2024-37762 CVSS 9.9

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

CVE-2024-38366 CVSS 10

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.

CVE-2024-38368 CVSS 9.3

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.

CVE-2024-38476 CVSS 9.8

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution v...

CVE-2024-38513 CVSS 10

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issu...

CVE-2024-39236 CVSS 9.8

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py.

CVE-2024-39251 CVSS 10

An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensit...

CVE-2024-39309 CVSS 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.

CVE-2024-5322 CVSS 9.1

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentica...

Critical 公開を見る

cvelogic Threat Intelligence