Home
» Risk & Exploitation
» Daily threat intelligence
» Mar 25, 2022
Mar 25, 2022 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Microsoft Windows: 7 CVEs added to CISA KEV today.
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2005-2773
HP OpenView Network Node Manager Remote Code Execution
Actively exploited (CISA KEV)
Listed on CISA KEV
Remote code execution exposure
Hewlett Packard (HP) OpenView Network Node Manager RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2022-24783
Deno is a runtime for JavaScript and TypeScript.
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
MiCollab, MiVoice Business Express Access Control
WatchGuard Firebox and XTM Appliances Arbitrary Code Execution
Microsoft Windows Print Spooler Privilege Escalation
Sitecore XP Remote Command Execution
Citrix ShareFile Improper Access Control
QNAP Helpdesk Improper Access Control
Sophos SG UTM Remote Code Execution
D-Link DIR-610 Devices Remote Command Execution
Palo Alto Networks PAN-OS Authentication Bypass
VMware Tanzu Spring Cloud Config Directory Traversal
Apache Kylin OS Command Injection
Juniper Junos OS Path Traversal
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian...
An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.
Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing...
Sophos Firewall Authentication Bypass
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of S...
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStat...
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files.
Deno is a runtime for JavaScript and TypeScript.
ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data.
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file.
View critical disclosures
cvelogic
Threat Intelligence