CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2021-45046

Ransomware

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Vendor: Apache

Product: Log4j2

Added: 2023-05-01

Due Date: 2023-05-22

Description:

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-917

CVE-2023-21839

Oracle WebLogic Server Unspecified Vulnerability

Vendor: Oracle

Product: WebLogic Server

Added: 2023-05-01

Due Date: 2023-05-22

Description:

Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.

Required Action:

Apply updates per vendor instructions.

CVE-2023-28432

MinIO Information Disclosure Vulnerability

Vendor: MinIO

Product: MinIO

Added: 2023-04-21

Due Date: 2023-05-12

Description:

MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2023-27350

Ransomware

PaperCut MF/NG Improper Access Control Vulnerability

Vendor: PaperCut

Product: MF/NG

Added: 2023-04-21

Due Date: 2023-05-12

Description:

PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2023-2136

Google Chrome Skia Integer Overflow Vulnerability

Vendor: Google

Product: Chromium Skia

Added: 2023-04-21

Due Date: 2023-05-12

Description:

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-190

CVE-2017-6742

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2023-04-19

Due Date: 2023-05-10

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2019-8526

Apple macOS Use-After-Free Vulnerability

Vendor: Apple

Product: macOS

Added: 2023-04-17

Due Date: 2023-05-08

Description:

Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2023-2033

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2023-04-17

Due Date: 2023-05-08

Description:

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2023-20963

Android Framework Privilege Escalation Vulnerability

Vendor: Android

Product: Framework

Added: 2023-04-13

Due Date: 2023-05-04

Description:

Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-295

CVE-2023-29492

Novi Survey Insecure Deserialization Vulnerability

Vendor: Novi Survey

Product: Novi Survey

Added: 2023-04-13

Due Date: 2023-05-04

Description:

Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2023-28252

Ransomware

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-04-11

Due Date: 2023-05-02

Description:

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2023-28205

Apple Multiple Products WebKit Use-After-Free Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2023-04-10

Due Date: 2023-05-01

Description:

Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2023-28206

Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and macOS

Added: 2023-04-10

Due Date: 2023-05-01

Description:

Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-27876

Ransomware

Veritas Backup Exec Agent File Access Vulnerability

Vendor: Veritas

Product: Backup Exec Agent

Added: 2023-04-07

Due Date: 2023-04-28

Description:

Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287

CVE-2021-27877

Ransomware

Veritas Backup Exec Agent Improper Authentication Vulnerability

Vendor: Veritas

Product: Backup Exec Agent

Added: 2023-04-07

Due Date: 2023-04-28

Description:

Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287