CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-9859

Apple Multiple Products Code Execution Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-415

CVE-2021-20090

Arcadyan Buffalo Firmware Path Traversal Vulnerability

Vendor: Arcadyan

Product: Buffalo Firmware

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-27562

Arm Trusted Firmware Out-of-Bounds Write Vulnerability

Vendor: Arm

Product: Trusted Firmware

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-28664

Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

Vendor: Arm

Product: Mali Graphics Processing Unit (GPU)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-28663

Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

Vendor: Arm

Product: Mali Graphics Processing Unit (GPU)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2019-3398

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Vendor: Atlassian

Product: Confluence Server and Data Center

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-26084

Ransomware

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Vendor: Atlassian

Product: Confluence Server and Data Center

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-917

CVE-2019-11580

Ransomware

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Vendor: Atlassian

Product: Crowd and Crowd Data Center

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

Required Action:

Apply updates per vendor instructions.

CVE-2019-3396

Ransomware

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Vendor: Atlassian

Product: Confluence Server and Data Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2021-42258

Ransomware

BQE BillQuick Web Suite SQL Injection Vulnerability

Vendor: BQE

Product: BillQuick Web Suite

Added: 2021-11-03

Due Date: 2021-11-17

Description:

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-89

CVE-2020-3452

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Vendor: Cisco

Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2020-3580

Ransomware

Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Vendor: Cisco

Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-79

CVE-2021-1497

Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

Vendor: Cisco

Product: HyperFlex HX

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2021-1498

Cisco HyperFlex HX Data Platform Command Injection Vulnerability

Vendor: Cisco

Product: HyperFlex HX

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-0171

Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20