CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-8196

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Vendor: Citrix

Product: Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2019-19781

Ransomware

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Vendor: Citrix

Product: Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2019-11634

Ransomware

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Vendor: Citrix

Product: Workspace Application and Receiver for Windows

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

Required Action:

Apply updates per vendor instructions.

CVE-2020-29557

D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

Vendor: D-Link

Product: DIR-825 R1 Devices

Added: 2021-11-03

Due Date: 2022-05-03

Description:

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2020-25506

D-Link DNS-320 Device Command Injection Vulnerability

Vendor: D-Link

Product: DNS-320 Device

Added: 2021-11-03

Due Date: 2022-05-03

Description:

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-15811

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

Vendor: DotNetNuke (DNN)

Product: DotNetNuke (DNN)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-326

CVE-2018-18325

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

Vendor: DotNetNuke (DNN)

Product: DotNetNuke (DNN)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-326

CVE-2017-9822

Ransomware

DotNetNuke (DNN) Remote Code Execution Vulnerability

Vendor: DotNetNuke (DNN)

Product: DotNetNuke (DNN)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2019-15752

Docker Desktop Community Edition Privilege Escalation Vulnerability

Vendor: Docker

Product: Desktop Community Edition

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-732

CVE-2020-8515

Multiple DrayTek Vigor Routers Web Management Page Vulnerability

Vendor: DrayTek

Product: Multiple Vigor Routers

Added: 2021-11-03

Due Date: 2022-05-03

Description:

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2018-7600

Ransomware

Drupal Core Remote Code Execution Vulnerability

Vendor: Drupal

Product: Drupal Core

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2021-22205

Ransomware

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Vendor: GitLab

Product: Community and Enterprise Editions

Added: 2021-11-03

Due Date: 2021-11-17

Description:

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-95

CVE-2018-6789

Ransomware

Exim Buffer Overflow Vulnerability

Vendor: Exim

Product: Exim

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2020-8657

EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

Vendor: EyesOfNetwork

Product: EyesOfNetwork

Added: 2021-11-03

Due Date: 2022-05-03

Description:

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-798

CVE-2020-8655

EyesOfNetwork Improper Privilege Management Vulnerability

Vendor: EyesOfNetwork

Product: EyesOfNetwork

Added: 2021-11-03

Due Date: 2022-05-03

Description:

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-269