CISA listet über 270 kritische Sicherheitslücken auf, die letzte Woche behoben wurden - Was gibt es Neues?

Teilen:

The Cybersecurity and Infrastructure Security Agency (CISA) has published its latest vulnerability bulletin, detailing over 270 security vulnerabilities identified in the past week across a wide range of software and hardware.

These vulnerabilities affect popular applications, operating systems, IoT devices, and development frameworks, posing significant risks if left unpatched.

The vulnerabilities have been categorized using the Common Vulnerability Scoring System (CVSS):

  • Critical (CVSS 9.0–10.0): Immediate attention required.
  • High (CVSS 7.0–8.9): Potential to cause major disruptions.
  • Medium (CVSS 4.0–6.9): Less severe but still actionable.
  • Low (CVSS 0.0–3.9): Minimal impact.

Nutzung der 2024 MITRE ATT&CK-Ergebnisse für KMU- und MSP-Cybersicherheitsverantwortliche - Teilnahme am kostenlosen Webinar

Top Critical Vulnerabilities

Several vulnerabilities have been classified as Critical (CVSS 10.0) due to their potential to enable remote code execution (RCE), unauthorized access, and data breaches.

ABB ASPECT-Enterprise Suite

Multiple critical flaws (e.g., CVE-2024-11317, CVE-2024-48839) allow attackers to exploit session fixation, remote code execution, and default credential misuse across products such as ASPECT, MATRIX, and NEXUS Series.

WordPress Plugins

Widely used plugins such as Roninwp FAT Services Booking (CVE-2024-54221) and Swift Performance Lite (CVE-2024-10516) are vulnerable to SQL injection, file inclusion, and XSS attacks.

IoT and Networking Devices

Devices such as Victure RX1800 WiFi Routers (CVE-2024-53940) and Zyxel VMG4005-B50A firmware (CVE-2024-9200) suffer from command injection vulnerabilities, allowing remote attackers to execute malicious code.

ROS2 (Robotic Operating System)

Buffer overflows and use-after-free vulnerabilities (e.g., CVE-2024-37861, CVE-2024-38920) in Open Robotics’ ROS2 can lead to denial-of-service attacks or arbitrary code execution.

Django

SQL injection vulnerabilities (e.g., CVE-2024-53908) in Django’s Oracle database implementations could expose applications to critical data manipulation risks.

Notable High-Severity Vulnerabilities

  • Google Chrome (CVE-2024-12053): A type confusion bug in Chrome’s V8 engine could allow attackers to corrupt objects, potentially leading to code execution via malicious web pages.
  • ABB ASPECT-Enterprise: Vulnerabilities like improper input validation (CVE-2024-51550) and data sanitization flaws (CVE-2024-51541) enable attackers to inject malicious scripts.
  • Android Devices: Various Android components are affected by out-of-bounds write flaws (e.g., CVE-2018-9430) and privilege escalation vulnerabilities (e.g., CVE-2018-9380).

Widespread Medium-Severity Issues

While not as urgent, medium-severity vulnerabilities (CVSS 4.0–6.9) still require action:

  • WordPress Themes and Plugins: Many are affected by XSS vulnerabilities, including TI WooCommerce Wishlist and Convert Forms for Joomla.
  • Development Frameworks: Issues in libraries like python-multipart could lead to denial-of-service attacks (CVE-2024-53981).

Vendor Breakdown

WordPress Plugins: A large portion of vulnerabilities stem from insecure WordPress plugins, such as Advanced File Manager (CVE-2024-11391) and Awesome Shortcodes (CVE-2024-54209). These vulnerabilities often allow unauthorized access or data injection.

Networking Devices: IoT and networking products, including those from Ruijie (CVE-2024-47547) and Lorex (CVE-2024-52547), have critical flaws that enable remote command execution or unauthorized data access.

Industrial Systems: Industrial systems from companies like ABB and Siemens (e.g., CVE-2024-52335) show vulnerabilities that could compromise operational technology environments.

Recommendations

CISA recommends immediate action to mitigate these vulnerabilities:

  1. Apply Patches: Update systems, firmware, and software to the latest versions.
  2. Strengthen Access Controls: Remove or disable default credentials and implement multi-factor authentication.
  3. Monitor Networks: Use intrusion detection systems to identify and respond to exploitation attempts.
  4. Regular Audits: Continuously assess infrastructure for potential vulnerabilities.

Users and organizations are urged to review the full CISA Vulnerability Bulletin and consult the respective CVE entries for detailed technical information and patching guidance. These vulnerabilities emphasize the critical need for proactive cybersecurity measures in an increasingly interconnected world.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:53 pm, März 16, 2025
Wetter-Symbol 9°C
L: 8° | H: 11°
broken clouds
Luftfeuchtigkeit: 55 %
Druck: 1024 mb
Wind: 12 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:12 am
Sonnenuntergang: 6:06 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
8° | 11°°C 0 mm 0% 11 mph 70 % 1026 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 10 mph 89 % 1029 mb 0 mm/h
Di. März 18 9:00 pm
Wetter-Symbol
4° | 10°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 7 mph 79 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 10°°C 0 mm 0% 11 mph 56 % 1024 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 8 mph 58 % 1024 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 3 mph 70 % 1026 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 84 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 89 % 1027 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 81 % 1028 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 7 mph 66 % 1029 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 52 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,746.85
-2.09%
Ethereum(ETH)
€1,723.66
-2.60%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.10
-6.34%
Solana(SOL)
€117.68
-5.14%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.153157
-5.42%
Shiba Inu(SHIB)
€0.000012
-1.22%
Pepe(PEPE)
€0.000006
-6.21%
Peanut das Eichhörnchen(PNUT)
€0.189019
20.47%
Nach oben scrollen