Nov 1, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 7 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-27582 Sick Sim1000 Fx Firmware privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Sick Sim1000 Fx Firmware privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-27584 Sick Sim2000st Firmware privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Sick Sim2000st Firmware privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-27585 Sick Sim1000 Fx Firmware privilege escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Sick Sim1000 Fx Firmware privilege escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-27582 CVSS 9.8

Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the use...

CVE-2022-27584 CVSS 9.8

Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlev...

CVE-2022-27585 CVSS 9.8

Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged rem...

CVE-2022-27586 CVSS 9.8

Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to...

CVE-2022-32941 CVSS 9.8

The issue was addressed with improved bounds checks.

CVE-2022-42808 CVSS 9.8

An out-of-bounds write issue was addressed with improved bounds checking.

CVE-2022-42813 CVSS 9.8

A certificate validation issue existed in the handling of WKWebView.

View critical disclosures

cvelogic Threat Intelligence