HomeSecurityCISA: Adds 8 vulnerabilities to the list of bugs used in...

CISA: Adds 8 vulnerabilities to list of bugs used in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added eight more vulnerabilities to its list of bugs known to be used in cyberattacks. The vulnerabilities include a mix of old and new bugs.

See also: Critical vulnerability in WordPress plugin affects thousands of sites

CISA vulnerabilities

CISA publishes these vulnerabilities to raise awareness of cybersecurity risks and to remind federal agencies of their obligation to promptly apply security updates to stay protected.

As we mentioned above, the 8 new additions to the list include vulnerabilities that are already being used in attacks. This means that they pose a significant risk to organizations and businesses, as they allow for the compromise of mobile devices, access to networks, the ability to execute commands remotely, etc.

See also: Bug: MacBook battery drains when in sleep mode

You can see the 8 vulnerabilities in the table below:

CVE IDDescriptionPatch Deadline
CVE-2022-22587Apple IOMobileFrameBuffer Memory Corruption Vulnerability2/11/2022
CVE-2021-20038SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability2/11/2022
CVE-2014-7169GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability7/28/2022
CVE-2014-6271GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability7/28/2022
CVE-2020-0787Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability7/28/2022
CVE-2014-1776Microsoft Internet Explorer Use-After-Free Vulnerability7/28/2022
CVE-2020-5722Grandstream Networks UCM6200 Series SQL Injection Vulnerability7/28/2022
CVE-2017-5689Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability7/28/2022

The most recent vulnerability, known as CVE-2022-22587, was discovered in 2022 and is a memory corruption bug in IOMobileFrameBuffer that affects iOS, iPadOS, and macOS “Monterey.” Apple released a security update to fix the zero-day last Wednesday. Due to the potential impact of this vulnerability on many devices, CISA has given federal agencies until February 11, 2022, to implement security updates.

CISA also added the vulnerability CVE-2021-20038 affecting SonicWall SMA 100 Appliances. Researchers discovered that cybercriminals were actively scanning and attempting to exploit this vulnerability. As a result, CISA is also requiring agencies to patch this bug by February 11, 2022.

See also: FBI: Warns of cyberattack on Beijing Olympics

As for the older flaws, CVE-2013-6271 is considered particularly critical. This vulnerability, along with other bugs, was used in old campaigns and large-scale DNS hijacking attacks.

With the addition of these eight bugs to CISA ’s Known Exploited Vulnerabilities, there are now a total of 351 vulnerabilities being used in attacks.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS