CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2022-43939

Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Vendor: Hitachi Vantara

Product: Pentaho Business Analytics (BA) Server

Added: 2025-03-03

Due Date: 2025-03-24

Description:

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-647

CVE-2023-20118

Cisco Small Business RV Series Routers Command Injection Vulnerability

Vendor: Cisco

Product: Small Business RV Series Routers

Added: 2025-03-03

Due Date: 2025-03-24

Description:

Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-77

CVE-2023-34192

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2025-02-25

Due Date: 2025-03-18

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-79

CVE-2024-49035

Microsoft Partner Center Improper Access Control Vulnerability

Vendor: Microsoft

Product: Partner Center

Added: 2025-02-25

Due Date: 2025-03-18

Description:

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-269

CVE-2024-20953

Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Vendor: Oracle

Product: Agile Product Lifecycle Management (PLM)

Added: 2025-02-24

Due Date: 2025-03-17

Description:

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2017-3066

Adobe ColdFusion Deserialization Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2025-02-24

Due Date: 2025-03-17

Description:

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-24989

Microsoft Power Pages Improper Access Control Vulnerability

Vendor: Microsoft

Product: Power Pages

Added: 2025-02-21

Due Date: 2025-03-14

Description:

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.

Required Action:

Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-284

CVE-2025-0111

Palo Alto Networks PAN-OS File Read Vulnerability

Vendor: Palo Alto Networks

Product: PAN-OS

Added: 2025-02-20

Due Date: 2025-03-13

Description:

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-73

CVE-2025-23209

Craft CMS Code Injection Vulnerability

Vendor: Craft CMS

Product: Craft CMS

Added: 2025-02-20

Due Date: 2025-03-13

Description:

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-0108

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Vendor: Palo Alto Networks

Product: PAN-OS

Added: 2025-02-18

Due Date: 2025-03-11

Description:

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-306

CVE-2024-53704

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

Vendor: SonicWall

Product: SonicOS

Added: 2025-02-18

Due Date: 2025-03-11

Description:

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-287

CVE-2024-57727

SimpleHelp Path Traversal Vulnerability

Vendor: SimpleHelp

Product: SimpleHelp

Added: 2025-02-13

Due Date: 2025-03-06

Description:

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2025-24200

Apple iOS and iPadOS Incorrect Authorization Vulnerability

Vendor: Apple

Product: iOS and iPadOS

Added: 2025-02-12

Due Date: 2025-03-05

Description:

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-863

CVE-2024-41710

Mitel SIP Phones Argument Injection Vulnerability

Vendor: Mitel

Product: SIP Phones

Added: 2025-02-12

Due Date: 2025-03-05

Description:

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-88

CVE-2024-40891

Zyxel DSL CPE OS Command Injection Vulnerability

Vendor: Zyxel

Product: DSL CPE Devices

Added: 2025-02-11

Due Date: 2025-03-04

Description:

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.

Required Action:

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CWEs:

CWE-78