HomeSecurityCISA adds Oracle and Mitel vulnerabilities to KEV List

CISA adds Oracle and Mitel vulnerabilities to KEV List

CISA has added critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab to the List of Known Exploitable Vulnerabilities (KEV) and is warning US federal agencies to protect their systems .

CISA Oracle and Mitel vulnerabilities KEV Catalog

The first vulnerability, which the service added to the Catalog, is a critical path traversal vulnerability (CVE-2024-41713), found in the NuPoint Unified Messaging (NPM) component of Mitel's MiCollab communications platform.

The vulnerability allows attackers to perform unauthorized administrative actions and access user and network information.

See also: CISA adds Windows kernel vulnerability to KEV List

The second vulnerability is CVE-2020-2883. It is found in Oracle WebLogic Server and was patched four years ago. It allows unauthorized attackers to take control of unpatched servers remotely.

CISA also warned of a second path traversal vulnerability in Mitel MiCollab (CVE-2024-55550), which could allow authorized attackers with administrative privileges to read arbitrary files on vulnerable servers. However, the impact is limited because successful exploitation does not allow escalation of privileges.

CISA added the three vulnerabilities to the KEV list yesterday and asked federal agencies to protect their networks by January 28.

See also: CISA adds Array Networks vulnerability to KEV List

CISA adds Oracle and Mitel vulnerabilities to KEV List

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.

The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

See also: CISA: Adds two Palo Alto Networks vulnerabilities to KEV list

Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS