2024年8月22日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2024-45166 An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12.

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Uci Idol2 RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2024-45167 An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12.

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Uci Idol2 RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2024-45169 An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12.

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Uci Idol2 RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2023-6452 CVSS 9.6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transactio...

CVE-2024-36439 CVSS 9.4

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's ha...

CVE-2024-36445 CVSS 9.8

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

CVE-2024-42773 CVSS 9.1

An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which a...

CVE-2024-42775 CVSS 9.1

An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which al...

CVE-2024-45163 CVSS 9.1

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server.

CVE-2024-45166 CVSS 9.8

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12.

CVE-2024-45167 CVSS 9.8

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12.

CVE-2024-45168 CVSS 9.1

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12.

CVE-2024-45169 CVSS 9.8

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12.

Critical 公開を見る

cvelogic Threat Intelligence