CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2021-35395

Realtek AP-Router SDK Buffer Overflow Vulnerability

Vendor: Realtek

Product: AP-Router SDK

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-122

CVE-2017-16651

Roundcube Webmail File Disclosure Vulnerability

Vendor: Roundcube

Product: Roundcube Webmail

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-552

CVE-2020-11652

SaltStack Salt Path Traversal Vulnerability

Vendor: SaltStack

Product: Salt

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2020-11651

SaltStack Salt Authentication Bypass Vulnerability

Vendor: SaltStack

Product: Salt

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

Required Action:

Apply updates per vendor instructions.

CVE-2020-16846

SaltStack Salt Shell Injection Vulnerability

Vendor: SaltStack

Product: Salt

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-2380

Ransomware

SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

Vendor: SAP

Product: Customer Relationship Management (CRM)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2010-5326

SAP NetWeaver Remote Code Execution Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

Required Action:

Apply updates per vendor instructions.

CVE-2016-9563

SAP NetWeaver XML External Entity (XXE) Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-611

CVE-2020-6287

SAP NetWeaver Missing Authentication for Critical Function Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2020-6207

SAP Solution Manager Missing Authentication for Critical Function Vulnerability

Vendor: SAP

Product: Solution Manager

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306

CVE-2016-3976

SAP NetWeaver Directory Traversal Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2019-16256

SIMalliance Toolbox Browser Command Injection Vulnerability

Vendor: SIMalliance

Product: Toolbox Browser

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.

Required Action:

Apply updates per vendor instructions.

CVE-2020-10148

SolarWinds Orion Authentication Bypass Vulnerability

Vendor: SolarWinds

Product: Orion

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-288

CVE-2021-35211

Ransomware

SolarWinds Serv-U Remote Code Execution Vulnerability

Vendor: SolarWinds

Product: Serv-U

Added: 2021-11-03

Due Date: 2021-11-17

Description:

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2016-3643

SolarWinds Virtualization Manager Privilege Escalation Vulnerability

Vendor: SolarWinds

Product: Virtualization Manager

Added: 2021-11-03

Due Date: 2022-05-03

Description:

SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264