CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2022-22674

Apple macOS Out-of-Bounds Read Vulnerability

Vendor: Apple

Product: macOS

Added: 2022-04-04

Due Date: 2022-04-25

Description:

macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-125

CVE-2021-45382

D-Link Multiple Routers Remote Code Execution Vulnerability

Vendor: D-Link

Product: Multiple Routers

Added: 2022-04-04

Due Date: 2022-04-25

Description:

A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-78

CVE-2022-26871

Trend Micro Apex Central Arbitrary File Upload Vulnerability

Vendor: Trend Micro

Product: Apex Central

Added: 2022-03-31

Due Date: 2022-04-21

Description:

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-184

CVE-2022-1040

Sophos Firewall Authentication Bypass Vulnerability

Vendor: Sophos

Product: Firewall

Added: 2022-03-31

Due Date: 2022-04-21

Description:

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-158

CVE-2021-34484

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-31

Due Date: 2022-04-21

Description:

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-269

CVE-2021-28799

Ransomware

QNAP NAS Improper Authorization Vulnerability

Vendor: QNAP

Product: Network Attached Storage (NAS)

Added: 2022-03-31

Due Date: 2022-04-21

Description:

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-285

CVE-2021-21551

Dell dbutil Driver Insufficient Access Control Vulnerability

Vendor: Dell

Product: dbutil Driver

Added: 2022-03-31

Due Date: 2022-04-21

Description:

Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-782

CVE-2018-10562

Ransomware

Dasan GPON Routers Command Injection Vulnerability

Vendor: Dasan

Product: Gigabit Passive Optical Network (GPON) Routers

Added: 2022-03-31

Due Date: 2022-04-21

Description:

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-78

CVE-2018-10561

Dasan GPON Routers Authentication Bypass Vulnerability

Vendor: Dasan

Product: Gigabit Passive Optical Network (GPON) Routers

Added: 2022-03-31

Due Date: 2022-04-21

Description:

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-287

CVE-2022-1096

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2022-0543

Debian-specific Redis Server Lua Sandbox Escape Vulnerability

Vendor: Redis

Product: Debian-specific Redis Servers

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-862

CVE-2021-38646

Ransomware

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CVE-2021-34486

Microsoft Windows Event Tracing Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2021-26085

Ransomware

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Vendor: Atlassian

Product: Confluence Server

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-425

CVE-2021-20028

Ransomware

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

Vendor: SonicWall

Product: Secure Remote Access (SRA)

Added: 2022-03-28

Due Date: 2022-04-18

Description:

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-89