CISA listet über 270 kritische Sicherheitslücken auf, die letzte Woche behoben wurden - Was gibt es Neues?

Teilen:

The Cybersecurity and Infrastructure Security Agency (CISA) has published its latest vulnerability bulletin, detailing over 270 security vulnerabilities identified in the past week across a wide range of software and hardware.

These vulnerabilities affect popular applications, operating systems, IoT devices, and development frameworks, posing significant risks if left unpatched.

The vulnerabilities have been categorized using the Common Vulnerability Scoring System (CVSS):

  • Critical (CVSS 9.0–10.0): Immediate attention required.
  • High (CVSS 7.0–8.9): Potential to cause major disruptions.
  • Medium (CVSS 4.0–6.9): Less severe but still actionable.
  • Low (CVSS 0.0–3.9): Minimal impact.

Nutzung der 2024 MITRE ATT&CK-Ergebnisse für KMU- und MSP-Cybersicherheitsverantwortliche - Teilnahme am kostenlosen Webinar

Top Critical Vulnerabilities

Several vulnerabilities have been classified as Critical (CVSS 10.0) due to their potential to enable remote code execution (RCE), unauthorized access, and data breaches.

ABB ASPECT-Enterprise Suite

Multiple critical flaws (e.g., CVE-2024-11317, CVE-2024-48839) allow attackers to exploit session fixation, remote code execution, and default credential misuse across products such as ASPECT, MATRIX, and NEXUS Series.

WordPress Plugins

Widely used plugins such as Roninwp FAT Services Booking (CVE-2024-54221) and Swift Performance Lite (CVE-2024-10516) are vulnerable to SQL injection, file inclusion, and XSS attacks.

IoT and Networking Devices

Devices such as Victure RX1800 WiFi Routers (CVE-2024-53940) and Zyxel VMG4005-B50A firmware (CVE-2024-9200) suffer from command injection vulnerabilities, allowing remote attackers to execute malicious code.

ROS2 (Robotic Operating System)

Buffer overflows and use-after-free vulnerabilities (e.g., CVE-2024-37861, CVE-2024-38920) in Open Robotics’ ROS2 can lead to denial-of-service attacks or arbitrary code execution.

Django

SQL injection vulnerabilities (e.g., CVE-2024-53908) in Django’s Oracle database implementations could expose applications to critical data manipulation risks.

Notable High-Severity Vulnerabilities

  • Google Chrome (CVE-2024-12053): A type confusion bug in Chrome’s V8 engine could allow attackers to corrupt objects, potentially leading to code execution via malicious web pages.
  • ABB ASPECT-Enterprise: Vulnerabilities like improper input validation (CVE-2024-51550) and data sanitization flaws (CVE-2024-51541) enable attackers to inject malicious scripts.
  • Android Devices: Various Android components are affected by out-of-bounds write flaws (e.g., CVE-2018-9430) and privilege escalation vulnerabilities (e.g., CVE-2018-9380).

Widespread Medium-Severity Issues

While not as urgent, medium-severity vulnerabilities (CVSS 4.0–6.9) still require action:

  • WordPress Themes and Plugins: Many are affected by XSS vulnerabilities, including TI WooCommerce Wishlist and Convert Forms for Joomla.
  • Development Frameworks: Issues in libraries like python-multipart could lead to denial-of-service attacks (CVE-2024-53981).

Vendor Breakdown

WordPress Plugins: A large portion of vulnerabilities stem from insecure WordPress plugins, such as Advanced File Manager (CVE-2024-11391) and Awesome Shortcodes (CVE-2024-54209). These vulnerabilities often allow unauthorized access or data injection.

Networking Devices: IoT and networking products, including those from Ruijie (CVE-2024-47547) and Lorex (CVE-2024-52547), have critical flaws that enable remote command execution or unauthorized data access.

Industrial Systems: Industrial systems from companies like ABB and Siemens (e.g., CVE-2024-52335) show vulnerabilities that could compromise operational technology environments.

Recommendations

CISA recommends immediate action to mitigate these vulnerabilities:

  1. Apply Patches: Update systems, firmware, and software to the latest versions.
  2. Strengthen Access Controls: Remove or disable default credentials and implement multi-factor authentication.
  3. Monitor Networks: Use intrusion detection systems to identify and respond to exploitation attempts.
  4. Regular Audits: Continuously assess infrastructure for potential vulnerabilities.

Users and organizations are urged to review the full CISA Vulnerability Bulletin and consult the respective CVE entries for detailed technical information and patching guidance. These vulnerabilities emphasize the critical need for proactive cybersecurity measures in an increasingly interconnected world.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:22 pm, Juni 15, 2025
Wetter-Symbol 21°C
L: 20° | H: 22°
broken clouds
Luftfeuchtigkeit: 50 %
Druck: 1024 mb
Wind: 11 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 57%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 22°°C 0 mm 0% 8 mph 53 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 7 mph 88 % 1028 mb 0 mm/h
Di. Juni 17 10:00 pm
Wetter-Symbol
16° | 26°°C 0 mm 0% 10 mph 78 % 1027 mb 0 mm/h
Mi. Juni 18 10:00 pm
Wetter-Symbol
15° | 25°°C 0 mm 0% 8 mph 72 % 1026 mb 0 mm/h
Do. Juni 19 10:00 pm
Wetter-Symbol
17° | 26°°C 0 mm 0% 12 mph 77 % 1027 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
19° | 20°°C 0 mm 0% 8 mph 53 % 1024 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 18°°C 0 mm 0% 5 mph 67 % 1026 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 3 mph 88 % 1027 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 3 mph 77 % 1028 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 4 mph 54 % 1028 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 4 mph 42 % 1028 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 7 mph 38 % 1026 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 7 mph 48 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,384.01
0.54%
Ethereum(ETH)
€2,208.61
1.48%
Fesseln(USDT)
€0.87
-0.01%
XRP(XRP)
€1.88
1.89%
Solana(SOL)
€132.31
6.00%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.151654
-1.01%
Shiba Inu(SHIB)
€0.000010
0.06%
Pepe(PEPE)
€0.000010
1.87%
Nach oben scrollen