2024年7月24日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2024-41110 Moby is an open-source project created by Docker for software containerization.

  • CVSS 9.9
  • 管理者/root への権限昇格の可能性

新たな重大公開(CVSS 9.9)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2024-36535 Layer5 Meshery privilege escalation

  • CVSS 9.8
  • 管理者/root への権限昇格の可能性

新たな重大 Layer5 Meshery privilege escalation(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2024-36536 Fabedge privilege escalation

  • CVSS 9.8
  • 管理者/root への権限昇格の可能性

新たな重大 Fabedge privilege escalation(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2024-36533 CVSS 9.8

Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account...

CVE-2024-36535 CVSS 9.8

Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service accoun...

CVE-2024-36536 CVSS 9.8

Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account...

CVE-2024-36539 CVSS 9.8

Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service accoun...

CVE-2024-36540 CVSS 9.8

Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the servi...

CVE-2024-41110 CVSS 9.9

Moby is an open-source project created by Docker for software containerization.

CVE-2024-41459 CVSS 9.8

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform...

CVE-2024-41460 CVSS 9.8

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteS...

CVE-2024-41461 CVSS 9.8

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpLis...

CVE-2024-41551 CVSS 9.8

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .

Critical 公開を見る

cvelogic Threat Intelligence