CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2016-1555

NETGEAR Multiple WAP Devices Command Injection Vulnerability

Vendor: NETGEAR

Product: Wireless Access Point (WAP) Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-77

CVE-2016-11021

D-Link DCS-930L Devices OS Command Injection Vulnerability

Vendor: D-Link

Product: DCS-930L Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-78

CVE-2016-10174

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

Vendor: NETGEAR

Product: WNR2000v5 Router

Added: 2022-03-25

Due Date: 2022-04-15

Description:

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2016-0752

Ruby on Rails Directory Traversal Vulnerability

Vendor: Rails

Product: Ruby on Rails

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2015-4068

Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

Vendor: Arcserve

Product: Unified Data Protection (UDP)

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2015-3035

TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Vendor: TP-Link

Product: Multiple Archer Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2015-1427

Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

Vendor: Elastic

Product: Elasticsearch

Added: 2022-03-25

Due Date: 2022-04-15

Description:

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2015-1187

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

Vendor: D-Link and TRENDnet

Product: Multiple Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-287

CVE-2015-0666

Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

Vendor: Cisco

Product: Prime Data Center Network Manager (DCNM)

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2014-6332

Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-25

Due Date: 2022-04-15

Description:

OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2014-6324

Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Kerberos Key Distribution Center (KDC)

Added: 2022-03-25

Due Date: 2022-04-15

Description:

The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2014-6287

Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

Vendor: Rejetto

Product: HTTP File Server (HFS)

Added: 2022-03-25

Due Date: 2022-04-15

Description:

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2014-3120

Elasticsearch Remote Code Execution Vulnerability

Vendor: Elastic

Product: Elasticsearch

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2014-0130

Ruby on Rails Directory Traversal Vulnerability

Vendor: Rails

Product: Ruby on Rails

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2013-5223

D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

Vendor: D-Link

Product: DSL-2760U

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-79