CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2019-10068

Kentico Xperience Deserialization of Untrusted Data Vulnerability

Vendor: Kentico

Product: Xperience

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2019-1003030

Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

Vendor: Jenkins

Product: Matrix Project Plugin

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CVE-2019-0903

Microsoft GDI Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Graphics Device Interface (GDI)

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.

Required Action:

Apply updates per vendor instructions.

CVE-2018-8414

Microsoft Windows Shell Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2018-8373

Microsoft Scripting Engine Memory Corruption Vulnerability

Vendor: Microsoft

Product: Internet Explorer Scripting Engine

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2018-6961

VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

Vendor: VMware

Product: SD-WAN Edge

Added: 2022-03-25

Due Date: 2022-04-15

Description:

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-14839

LG N1A1 NAS Remote Command Execution Vulnerability

Vendor: LG

Product: N1A1 NAS

Added: 2022-03-25

Due Date: 2022-04-15

Description:

LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-1273

Ransomware

VMware Tanzu Spring Data Commons Property Binder Vulnerability

Vendor: VMware Tanzu

Product: Spring Data Commons

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2018-11138

Ransomware

Quest KACE System Management Appliance Remote Command Execution Vulnerability

Vendor: Quest

Product: KACE System Management Appliance

Added: 2022-03-25

Due Date: 2022-04-15

Description:

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-0147

Cisco Secure Access Control System Java Deserialization Vulnerability

Vendor: Cisco

Product: Secure Access Control System (ACS)

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2018-0125

Cisco VPN Routers Remote Code Execution Vulnerability

Vendor: Cisco

Product: VPN Routers

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-6334

NETGEAR DGN2200 Devices OS Command Injection Vulnerability

Vendor: NETGEAR

Product: DGN2200 Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-78

CVE-2017-6316

Citrix Multiple Products Remote Code Execution Vulnerability

Vendor: Citrix

Product: NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-3881

Cisco IOS and IOS XE Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-12617

Apache Tomcat Remote Code Execution Vulnerability

Vendor: Apache

Product: Tomcat

Added: 2022-03-25

Due Date: 2022-04-15

Description:

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-434