CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2022-24990

Ransomware

TerraMaster OS Remote Command Execution Vulnerability

Vendor: TerraMaster

Product: TerraMaster OS

Added: 2023-02-10

Due Date: 2023-03-03

Description:

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2023-0669

Ransomware

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Vendor: Fortra

Product: GoAnywhere MFT

Added: 2023-02-10

Due Date: 2023-03-03

Description:

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2022-21587

Ransomware

Oracle E-Business Suite Unspecified Vulnerability

Vendor: Oracle

Product: E-Business Suite

Added: 2023-02-02

Due Date: 2023-02-23

Description:

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2023-22952

Multiple SugarCRM Products Remote Code Execution Vulnerability

Vendor: SugarCRM

Product: Multiple Products

Added: 2023-02-02

Due Date: 2023-02-23

Description:

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-11357

Ransomware

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Vendor: Telerik

Product: User Interface (UI) for ASP.NET AJAX

Added: 2023-01-26

Due Date: 2023-02-16

Description:

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2022-47966

Ransomware

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Vendor: Zoho

Product: ManageEngine

Added: 2023-01-23

Due Date: 2023-02-13

Description:

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Required Action:

Apply updates per vendor instructions.

CVE-2022-44877

CWP Control Web Panel OS Command Injection Vulnerability

Vendor: CWP

Product: Control Web Panel

Added: 2023-01-17

Due Date: 2023-02-07

Description:

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2022-41080

Ransomware

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Exchange Server

Added: 2023-01-10

Due Date: 2023-01-31

Description:

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CVE-2023-21674

Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-01-10

Due Date: 2023-01-31

Description:

Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2018-5430

TIBCO JasperReports Server Information Disclosure Vulnerability

Vendor: TIBCO

Product: JasperReports

Added: 2022-12-29

Due Date: 2023-01-19

Description:

TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2018-18809

TIBCO JasperReports Library Directory Traversal Vulnerability

Vendor: TIBCO

Product: JasperReports

Added: 2022-12-29

Due Date: 2023-01-19

Description:

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2022-42856

Apple iOS Type Confusion Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-12-14

Due Date: 2023-01-04

Description:

Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2022-42475

Ransomware

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Vendor: Fortinet

Product: FortiOS

Added: 2022-12-13

Due Date: 2023-01-03

Description:

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-197

CVE-2022-44698

Ransomware

Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

Vendor: Microsoft

Product: Defender

Added: 2022-12-13

Due Date: 2023-01-03

Description:

Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-755

CVE-2022-27518

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Vendor: Citrix

Product: Application Delivery Controller (ADC) and Gateway

Added: 2022-12-13

Due Date: 2023-01-03

Description:

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-664