CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2024-43451

Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2024-11-12

Due Date: 2024-12-03

Description:

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-73

CVE-2024-49039

Ransomware

Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2024-11-12

Due Date: 2024-12-03

Description:

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-287

CVE-2019-16278

Nostromo nhttpd Directory Traversal Vulnerability

Vendor: Nostromo

Product: nhttpd

Added: 2024-11-07

Due Date: 2024-11-28

Description:

Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2024-51567

Ransomware

CyberPanel Incorrect Default Permissions Vulnerability

Vendor: CyberPersons

Product: CyberPanel

Added: 2024-11-07

Due Date: 2024-11-28

Description:

CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-276

CVE-2024-43093

Android Framework Privilege Escalation Vulnerability

Vendor: Android

Product: Framework

Added: 2024-11-07

Due Date: 2024-11-28

Description:

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-5910

Palo Alto Networks Expedition Missing Authentication Vulnerability

Vendor: Palo Alto Networks

Product: Expedition

Added: 2024-11-07

Due Date: 2024-11-28

Description:

Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-306

CVE-2024-8956

PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

Vendor: PTZOptics

Product: PT30X-SDI/NDI Cameras

Added: 2024-11-04

Due Date: 2024-11-25

Description:

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-287

CVE-2024-8957

PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

Vendor: PTZOptics

Product: PT30X-SDI/NDI Cameras

Added: 2024-11-04

Due Date: 2024-11-25

Description:

PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2024-37383

RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability

Vendor: Roundcube

Product: Webmail

Added: 2024-10-24

Due Date: 2024-11-14

Description:

RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-79

CVE-2024-20481

Cisco ASA and FTD Denial-of-Service Vulnerability

Vendor: Cisco

Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Added: 2024-10-24

Due Date: 2024-11-14

Description:

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-772

CVE-2024-47575

Fortinet FortiManager Missing Authentication Vulnerability

Vendor: Fortinet

Product: FortiManager

Added: 2024-10-23

Due Date: 2024-11-13

Description:

Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-306

CVE-2024-38094

Ransomware

Microsoft SharePoint Deserialization Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2024-10-22

Due Date: 2024-11-12

Description:

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2024-9537

ScienceLogic SL1 Unspecified Vulnerability

Vendor: ScienceLogic

Product: SL1

Added: 2024-10-21

Due Date: 2024-11-11

Description:

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-40711

Ransomware

Veeam Backup and Replication Deserialization Vulnerability

Vendor: Veeam

Product: Backup & Replication

Added: 2024-10-17

Due Date: 2024-11-07

Description:

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2024-28987

SolarWinds Web Help Desk Hardcoded Credential Vulnerability

Vendor: SolarWinds

Product: Web Help Desk

Added: 2024-10-15

Due Date: 2024-11-05

Description:

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-798