2024年7月15日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • OSGeo GeoServer が CISA KEV に新規掲載 — 実環境での悪用を確認。
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

実際の悪用を確認

CVE-2024-36401 OSGeo GeoServer GeoTools Eval Injection

  • 実環境での悪用(CISA KEV)
  • CISA KEV に掲載
  • リモートコード実行の露出リスク

OSGeo GeoServer RCE は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。

重大な露出リスク

CVE-2024-39915 Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the...

  • CVSS 9.9
  • リモートコード実行の露出リスク

新たな重大公開(CVSS 9.9)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2024-40414 新たな重大 Tenda Ax1806 Firmware Buffer Overflow が公開。

  • CVSS 9.8

新たな重大 Tenda Ax1806 Firmware Buffer Overflow(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2024-36455 CVSS 9.4

An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending...

CVE-2024-36456 CVSS 9.4

This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a speci...

CVE-2024-38492 CVSS 9.4

This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a speci...

CVE-2024-39915 CVSS 9.9

Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API.

CVE-2024-40414 CVSS 9.8

新たな重大 Tenda Ax1806 Firmware Buffer Overflow が公開。

CVE-2024-40415 CVSS 9.8

新たな重大 Tenda Ax1806 Firmware Buffer Overflow が公開。

CVE-2024-40416 CVSS 9.8

新たな重大 Tenda Ax1806 Firmware Buffer Overflow が公開。

CVE-2024-40524 CVSS 9.8

Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application....

CVE-2024-40624 CVSS 9.8

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php.

CVE-2024-4143 CVSS 9.8

A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution.

Critical 公開を見る

cvelogic Threat Intelligence