CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-21334

Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-01-14

Due Date: 2025-02-04

Description:

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2025-21333

Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-01-14

Due Date: 2025-02-04

Description:

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-122

CVE-2024-55591

Ransomware

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Vendor: Fortinet

Product: FortiOS and FortiProxy

Added: 2025-01-14

Due Date: 2025-01-21

Description:

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-288

CVE-2023-48365

Ransomware

Qlik Sense HTTP Tunneling Vulnerability

Vendor: Qlik

Product: Sense

Added: 2025-01-13

Due Date: 2025-02-03

Description:

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-444

CVE-2024-12686

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

Vendor: BeyondTrust

Product: Privileged Remote Access (PRA) and Remote Support (RS)

Added: 2025-01-13

Due Date: 2025-02-03

Description:

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-0282

Ransomware

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Vendor: Ivanti

Product: Connect Secure, Policy Secure, and ZTA Gateways

Added: 2025-01-08

Due Date: 2025-01-15

Description:

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

Required Action:

Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

CWEs:

CWE-121

CVE-2020-2883

Oracle WebLogic Server Unspecified Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2025-01-07

Due Date: 2025-01-28

Description:

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-55550

Ransomware

Mitel MiCollab Path Traversal Vulnerability

Vendor: Mitel

Product: MiCollab

Added: 2025-01-07

Due Date: 2025-01-28

Description:

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2024-41713

Ransomware

Mitel MiCollab Path Traversal Vulnerability

Vendor: Mitel

Product: MiCollab

Added: 2025-01-07

Due Date: 2025-01-28

Description:

Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2024-3393

Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability

Vendor: Palo Alto Networks

Product: PAN-OS

Added: 2024-12-30

Due Date: 2025-01-20

Description:

Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-754

CVE-2021-44207

Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

Vendor: Acclaim Systems

Product: USAHERDS

Added: 2024-12-23

Due Date: 2025-01-13

Description:

Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.

CWEs:

CWE-798

CVE-2024-12356

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

Vendor: BeyondTrust

Product: Privileged Remote Access (PRA) and Remote Support (RS)

Added: 2024-12-19

Due Date: 2024-12-27

Description:

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-77

CVE-2021-40407

Reolink RLC-410W IP Camera OS Command Injection Vulnerability

Vendor: Reolink

Product: RLC-410W IP Camera

Added: 2024-12-18

Due Date: 2025-01-08

Description:

Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.

Required Action:

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CWEs:

CWE-78

CVE-2019-11001

Reolink Multiple IP Cameras OS Command Injection Vulnerability

Vendor: Reolink

Product: Multiple IP Cameras

Added: 2024-12-18

Due Date: 2025-01-08

Description:

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

Required Action:

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CWEs:

CWE-78

CVE-2022-23227

NUUO NVRmini2 Devices Missing Authentication Vulnerability

Vendor: NUUO

Product: NVRmini2 Devices

Added: 2024-12-18

Due Date: 2025-01-08

Description:

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

Required Action:

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CWEs:

CWE-306