CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2017-12240

Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-12238

Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

Vendor: Cisco

Product: Catalyst 6800 Series Switches

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2017-12237

Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2017-12235

Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-12234

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-12233

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2017-12232

Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2017-12231

Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2017-11826

Microsoft Office Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-11292

Adobe Flash Player Type Confusion Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-843

CVE-2017-0261

Microsoft Office Use-After-Free Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2017-0001

Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Graphics Device Interface (GDI)

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges

Required Action:

Apply updates per vendor instructions.

CVE-2016-8562

Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

Vendor: Siemens

Product: SIMATIC CP

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2016-7855

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-416

CVE-2016-7262

Microsoft Office Security Feature Bypass Vulnerability

Vendor: Microsoft

Product: Excel

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20