CISA listet über 270 kritische Sicherheitslücken auf, die letzte Woche behoben wurden - Was gibt es Neues?

Teilen:

The Cybersecurity and Infrastructure Security Agency (CISA) has published its latest vulnerability bulletin, detailing over 270 security vulnerabilities identified in the past week across a wide range of software and hardware.

These vulnerabilities affect popular applications, operating systems, IoT devices, and development frameworks, posing significant risks if left unpatched.

The vulnerabilities have been categorized using the Common Vulnerability Scoring System (CVSS):

  • Critical (CVSS 9.0–10.0): Immediate attention required.
  • High (CVSS 7.0–8.9): Potential to cause major disruptions.
  • Medium (CVSS 4.0–6.9): Less severe but still actionable.
  • Low (CVSS 0.0–3.9): Minimal impact.

Nutzung der 2024 MITRE ATT&CK-Ergebnisse für KMU- und MSP-Cybersicherheitsverantwortliche - Teilnahme am kostenlosen Webinar

Top Critical Vulnerabilities

Several vulnerabilities have been classified as Critical (CVSS 10.0) due to their potential to enable remote code execution (RCE), unauthorized access, and data breaches.

ABB ASPECT-Enterprise Suite

Multiple critical flaws (e.g., CVE-2024-11317, CVE-2024-48839) allow attackers to exploit session fixation, remote code execution, and default credential misuse across products such as ASPECT, MATRIX, and NEXUS Series.

WordPress Plugins

Widely used plugins such as Roninwp FAT Services Booking (CVE-2024-54221) and Swift Performance Lite (CVE-2024-10516) are vulnerable to SQL injection, file inclusion, and XSS attacks.

IoT and Networking Devices

Devices such as Victure RX1800 WiFi Routers (CVE-2024-53940) and Zyxel VMG4005-B50A firmware (CVE-2024-9200) suffer from command injection vulnerabilities, allowing remote attackers to execute malicious code.

ROS2 (Robotic Operating System)

Buffer overflows and use-after-free vulnerabilities (e.g., CVE-2024-37861, CVE-2024-38920) in Open Robotics’ ROS2 can lead to denial-of-service attacks or arbitrary code execution.

Django

SQL injection vulnerabilities (e.g., CVE-2024-53908) in Django’s Oracle database implementations could expose applications to critical data manipulation risks.

Notable High-Severity Vulnerabilities

  • Google Chrome (CVE-2024-12053): A type confusion bug in Chrome’s V8 engine could allow attackers to corrupt objects, potentially leading to code execution via malicious web pages.
  • ABB ASPECT-Enterprise: Vulnerabilities like improper input validation (CVE-2024-51550) and data sanitization flaws (CVE-2024-51541) enable attackers to inject malicious scripts.
  • Android Devices: Various Android components are affected by out-of-bounds write flaws (e.g., CVE-2018-9430) and privilege escalation vulnerabilities (e.g., CVE-2018-9380).

Widespread Medium-Severity Issues

While not as urgent, medium-severity vulnerabilities (CVSS 4.0–6.9) still require action:

  • WordPress Themes and Plugins: Many are affected by XSS vulnerabilities, including TI WooCommerce Wishlist and Convert Forms for Joomla.
  • Development Frameworks: Issues in libraries like python-multipart could lead to denial-of-service attacks (CVE-2024-53981).

Vendor Breakdown

WordPress Plugins: A large portion of vulnerabilities stem from insecure WordPress plugins, such as Advanced File Manager (CVE-2024-11391) and Awesome Shortcodes (CVE-2024-54209). These vulnerabilities often allow unauthorized access or data injection.

Networking Devices: IoT and networking products, including those from Ruijie (CVE-2024-47547) and Lorex (CVE-2024-52547), have critical flaws that enable remote command execution or unauthorized data access.

Industrial Systems: Industrial systems from companies like ABB and Siemens (e.g., CVE-2024-52335) show vulnerabilities that could compromise operational technology environments.

Recommendations

CISA recommends immediate action to mitigate these vulnerabilities:

  1. Apply Patches: Update systems, firmware, and software to the latest versions.
  2. Strengthen Access Controls: Remove or disable default credentials and implement multi-factor authentication.
  3. Monitor Networks: Use intrusion detection systems to identify and respond to exploitation attempts.
  4. Regular Audits: Continuously assess infrastructure for potential vulnerabilities.

Users and organizations are urged to review the full CISA Vulnerability Bulletin and consult the respective CVE entries for detailed technical information and patching guidance. These vulnerabilities emphasize the critical need for proactive cybersecurity measures in an increasingly interconnected world.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:11 pm, Apr. 22, 2025
Wetter-Symbol 17°C
L: 16° | H: 18°
overcast clouds
Luftfeuchtigkeit: 44 %
Druck: 1016 mb
Wind: 9 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 94%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:49 am
Sonnenuntergang: 8:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 18°°C 0 mm 0% 11 mph 66 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
8° | 11°°C 1 mm 100% 13 mph 95 % 1018 mb 0 mm/h
Do. Apr. 24 10:00 pm
Wetter-Symbol
9° | 15°°C 0.2 mm 20% 6 mph 86 % 1024 mb 0 mm/h
Fr. Apr. 25 10:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 8 mph 87 % 1024 mb 0 mm/h
Sa. Apr. 26 10:00 pm
Wetter-Symbol
9° | 13°°C 0.6 mm 60% 4 mph 96 % 1024 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
14° | 16°°C 0 mm 0% 11 mph 48 % 1016 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
10° | 12°°C 0 mm 0% 7 mph 66 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 76 % 1013 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 10 mph 95 % 1010 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
9° | 9°°C 1 mm 100% 12 mph 94 % 1009 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
8° | 8°°C 1 mm 100% 13 mph 93 % 1010 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
8° | 8°°C 0.8 mm 80% 10 mph 91 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
11° | 11°°C 0 mm 0% 10 mph 73 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€79,010.49
2.94%
Ethereum(ETH)
€1,455.56
2.51%
Fesseln(USDT)
€0.87
0.02%
XRP(XRP)
€1.87
1.02%
Solana(SOL)
€125.51
3.34%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.149439
6.11%
Shiba Inu(SHIB)
€0.000011
3.19%
Pepe(PEPE)
€0.000007
5.75%
Nach oben scrollen