CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2021-25297

Nagios XI OS Command Injection

Vendor: Nagios

Product: Nagios XI

Added: 2022-01-18

Due Date: 2022-02-01

Description:

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78 CWE-138

CVE-2021-25298

Nagios XI OS Command Injection

Vendor: Nagios

Product: Nagios XI

Added: 2022-01-18

Due Date: 2022-02-01

Description:

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78 CWE-138

CVE-2021-40870

Aviatrix Controller Unrestricted Upload of File

Vendor: Aviatrix

Product: Aviatrix Controller

Added: 2022-01-18

Due Date: 2022-02-01

Description:

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-25 CWE-96

CVE-2021-33766

Microsoft Exchange Server Information Disclosure

Vendor: Microsoft

Product: Exchange Server

Added: 2022-01-18

Due Date: 2022-02-01

Description:

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287

CVE-2021-21975

Ransomware

VMware Server Side Request Forgery in vRealize Operations Manager API

Vendor: VMware

Product: vRealize Operations Manager API

Added: 2022-01-18

Due Date: 2022-02-01

Description:

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-918

CVE-2021-21315

System Information Library for Node.JS Command Injection

Vendor: Npm package

Product: System Information Library for Node.JS

Added: 2022-01-18

Due Date: 2022-02-01

Description:

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2021-22991

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

Vendor: F5

Product: BIG-IP Traffic Management Microkernel

Added: 2022-01-18

Due Date: 2022-02-01

Description:

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2020-14864

Oracle Business Intelligence Enterprise Edition Path Transversal

Vendor: Oracle

Product: Intelligence Enterprise Edition

Added: 2022-01-18

Due Date: 2022-07-18

Description:

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2020-13671

Drupal core Un-restricted Upload of File

Vendor: Drupal

Product: Drupal core

Added: 2022-01-18

Due Date: 2022-07-18

Description:

Improper sanitization in the extension file names is present in Drupal core.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-434

CVE-2020-11978

Apache Airflow Command Injection

Vendor: Apache

Product: Airflow

Added: 2022-01-18

Due Date: 2022-07-18

Description:

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2020-13927

Apache Airflow's Experimental API Authentication Bypass

Vendor: Apache

Product: Airflow's Experimental API

Added: 2022-01-18

Due Date: 2022-07-18

Description:

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-1188 CWE-306

CVE-2021-22017

VMware vCenter Server Improper Access Control

Vendor: VMware

Product: vCenter Server

Added: 2022-01-10

Due Date: 2022-01-24

Description:

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-23

CVE-2021-36260

Hikvision Improper Input Validation

Vendor: Hikvision

Product: Security cameras web server

Added: 2022-01-10

Due Date: 2022-01-24

Description:

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2020-6572

Google Chrome Media Use-After-Free Vulnerability

Vendor: Google

Product: Chrome Media

Added: 2022-01-10

Due Date: 2022-07-10

Description:

Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2019-1458

Ransomware

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Win32k

Added: 2022-01-10

Due Date: 2022-07-10

Description:

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

Required Action:

Apply updates per vendor instructions.