CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2022-20699

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco

Product: Small Business RV160, RV260, RV340, and RV345 Series Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-785

CVE-2021-41379

Ransomware

Microsoft Windows Installer Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-03

Due Date: 2022-03-17

Description:

Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-1386

CVE-2020-1938

Apache Tomcat Improper Privilege Management Vulnerability

Vendor: Apache

Product: Tomcat

Added: 2022-03-03

Due Date: 2022-03-17

Description:

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Required Action:

Apply updates per vendor instructions.

CVE-2020-11899

Treck TCP/IP stack Out-of-Bounds Read Vulnerability

Vendor: Treck TCP/IP stack

Product: IPv6

Added: 2022-03-03

Due Date: 2022-03-17

Description:

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-125

CVE-2019-16928

Exim Out-of-bounds Write Vulnerability

Vendor: Exim

Product: Exim Internet Mailer

Added: 2022-03-03

Due Date: 2022-03-17

Description:

Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-1652

Cisco Small Business Routers Improper Input Validation Vulnerability

Vendor: Cisco

Product: Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2019-1297

Microsoft Excel Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Excel

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.

Required Action:

Apply updates per vendor instructions.

CVE-2018-8581

Ransomware

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Exchange Server

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.

Required Action:

Apply updates per vendor instructions.

CVE-2018-8298

ChakraCore Scripting Engine Type Confusion Vulnerability

Vendor: ChakraCore

Product: ChakraCore scripting engine

Added: 2022-03-03

Due Date: 2022-03-17

Description:

The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2018-0180

Cisco IOS Software Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2018-0179

Cisco IOS Software Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2018-0175

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Vendor: Cisco

Product: IOS, XR, and XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2018-0174

Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

Vendor: Cisco

Product: IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2018-0173

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2018-0172

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20