CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

CISA Adds Three Security Flaws with Active Exploitation to KEV Catalog

admin by admin
November 17, 2023
in Information Security


Nov 17, 2023NewsroomPatch Management / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation in the wild.

The vulnerabilities are as follows –

  • CVE-2023-36584 (CVSS score: 5.4) – Microsoft Windows Mark-of-the-Web (MotW) Security Feature Bypass Vulnerability
  • CVE-2023-1671 (CVSS score: 9.8) – Sophos Web Appliance Command Injection Vulnerability
  • CVE-2023-2551 (CVSS score: 8.8) – Oracle Fusion Middleware Unspecified Vulnerability

CVE-2023-1671 relates to a critical pre-auth command injection vulnerability that allows for the execution of arbitrary code. CVE-2023-2551 is a flaw in the WLS Core Components that allows an unauthenticated attacker with network access to compromise the WebLogic Server.

Cybersecurity

There are currently no public reports documenting in-the-wild attacks leveraging the two flaws.

On the other hand, the addition of CVE-2023-36584 to the KEV catalog is based on a report from Palo Alto Networks Unit 42 earlier this week, which detailed spear-phishing attacks mounted by pro-Russian APT group known as Storm-0978 (aka RomCom or Void Rabisu) targeting groups supporting Ukraine’s admission into NATO in July 2023.

CVE-2023-36584, patched by Microsoft as part of October 2023 security updates, is said to have been used alongside CVE-2023-36884, a Windows remote code execution vulnerability addressed in July, in an exploit chain to deliver PEAPOD, an updated version of RomCom RAT.

In light of active exploitation, federal agencies are recommended to apply the fixes by December 7, 2023, to secure their networks against potential threats.

Fortinet Discloses Critical Command Injection Bug in FortiSIEM

The development comes as Fortinet is alerting customers of a critical command injection vulnerability in FortiSIEM report server (CVE-2023-36553, CVSS score: 9.3) that could be exploited by attackers to execute arbitrary commands.

Cybersecurity

CVE-2023-36553 has been described as a variant of CVE-2023-34992 (CVSS score: 9.7), a similar flaw in the same product that was remediated by Fortinet in early October 2023.

“An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSIEM report server may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests,” the company said in an advisory this week.

The vulnerability, which impacts FortiSIEM versions 4.7, 4.9, 4.10, 5.0, 5.1, 5.2, 5.3, and 5.4, has been fixed in versions 7.1.0, 7.0.1, 6.7.6, 6.6.4, 6.5.2, 6.4.3, or later.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

Use scalable controls for AWS services accessing your resources

Next Post

Leveraging ITSM, AI, and ESM for Digital Evolution

Related Posts

Information Security

New PoolParty Process Injection Techniques Outsmart Top EDR Solutions

by admin
December 11, 2023
Information Security

New Spectre-based Vulnerability Impacts Intel, AMD, and Arm CPUs

by admin
December 10, 2023
Information Security

Researchers Unveal GuLoader Malware’s Latest Anti-Analysis Techniques

by admin
December 9, 2023
Information Security

2023 ISO and CSA STAR certificates now available with ISO 27001 transition from 2013 to 2022 version

by admin
December 9, 2023
Information Security

Founder of Bitzlato Cryptocurrency Exchange Pleads Guilty in Money-Laundering Scheme

by admin
December 8, 2023
Next Post

Leveraging ITSM, AI, and ESM for Digital Evolution

Recommended

New PoolParty Process Injection Techniques Outsmart Top EDR Solutions

December 11, 2023

Information Paradox ~ Future of CIO

December 10, 2023

New Spectre-based Vulnerability Impacts Intel, AMD, and Arm CPUs

December 10, 2023

Innovateviastronggovernance

December 9, 2023

Technology Innovation of the Year for Summit’s Service Automation Solution

December 9, 2023

Researchers Unveal GuLoader Malware’s Latest Anti-Analysis Techniques

December 9, 2023

© CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 CIO News Hubb All rights reserved.