CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2019-11634

Ransomware

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Vendor: Citrix

Product: Workspace Application and Receiver for Windows

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

Required Action:

Apply updates per vendor instructions.

CVE-2020-29557

D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

Vendor: D-Link

Product: DIR-825 R1 Devices

Added: 2021-11-03

Due Date: 2022-05-03

Description:

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2020-25506

D-Link DNS-320 Device Command Injection Vulnerability

Vendor: D-Link

Product: DNS-320 Device

Added: 2021-11-03

Due Date: 2022-05-03

Description:

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-15811

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

Vendor: DotNetNuke (DNN)

Product: DotNetNuke (DNN)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-326

CVE-2018-18325

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

Vendor: DotNetNuke (DNN)

Product: DotNetNuke (DNN)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-326

CVE-2017-9822

Ransomware

DotNetNuke (DNN) Remote Code Execution Vulnerability

Vendor: DotNetNuke (DNN)

Product: DotNetNuke (DNN)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2019-15752

Docker Desktop Community Edition Privilege Escalation Vulnerability

Vendor: Docker

Product: Desktop Community Edition

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-732

CVE-2020-8515

Multiple DrayTek Vigor Routers Web Management Page Vulnerability

Vendor: DrayTek

Product: Multiple Vigor Routers

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-7600

Ransomware

Drupal Core Remote Code Execution Vulnerability

Vendor: Drupal

Product: Drupal Core

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2021-22205

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Vendor: GitLab

Product: Community and Enterprise Editions

Added: 2021-11-03

Due Date: 2021-11-17

Description:

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-95

CVE-2018-6789

Ransomware

Exim Buffer Overflow Vulnerability

Vendor: Exim

Product: Exim

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2020-8657

EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

Vendor: EyesOfNetwork

Product: EyesOfNetwork

Added: 2021-11-03

Due Date: 2022-05-03

Description:

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-798

CVE-2020-8655

EyesOfNetwork Improper Privilege Management Vulnerability

Vendor: EyesOfNetwork

Product: EyesOfNetwork

Added: 2021-11-03

Due Date: 2022-05-03

Description:

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-269

CVE-2020-5902

Ransomware

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

Vendor: F5

Product: BIG-IP

Added: 2021-11-03

Due Date: 2022-05-03

Description:

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-22986

Ransomware

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

Vendor: F5

Product: BIG-IP and BIG-IQ Centralized Management

Added: 2021-11-03

Due Date: 2021-11-17

Description:

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-863