CISA

CISA warns of critical Oracle, Mitel flaws exploited in attacks

Teilen:

CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.

The cybersecurity agency added a critical path traversal vulnerability (CVE-2024-41713) found in the NuPoint Unified Messaging (NPM) component Mitel’s MiCollab unified communications platform to its Known Exploited Vulnerabilities Catalog.

This security bug allows attackers to perform unauthorized administrative actions and access user and network information.

“A successful exploit of this vulnerability could allow an attacker to gain unauthorized access, with potential impacts to the confidentiality, integrity, and availability of the system. This vulnerability is exploitable without authentication,” MiCollab explains.

“If the vulnerability is successfully exploited, an attacker could gain unauthenticated access to provisioning information including non-sensitive user and network information and perform unauthorized administrative actions on the MiCollab Server.”

The critical Oracle WebLogic Server flaw tracked as CVE-2020-2883 and patched four years ago in April 2020 enables unauthenticated attackers to take unpatched servers remotely.

The U.S. cybersecurity agency also warned of a second Mitel MiCollab path traversal vulnerability (CVE-2024-55550), enabling authenticated attackers with admin privileges to read arbitrary files on vulnerable servers. However, the impact is limited because successful exploitation doesn’t allow privilege escalation, and accessible files don’t contain sensitive system information.

Today, CISA added all three vulnerabilities to its Known Exploited Vulnerabilities catalog, tagging them as actively exploited. As mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021, Federal Civilian Executive Branch (FCEB) agencies must secure their networks within three weeks by January 28.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA said on Tuesday.

While the KEV catalog focuses on alerting U.S. federal agencies regarding vulnerabilities that should be patched as soon as possible, all organizations are advised to prioritize mitigating these security flaws to block ongoing attacks.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:10 am, Juni 8, 2025
Wetter-Symbol 10°C
L: 9° | H: 11°
broken clouds
Luftfeuchtigkeit: 91 %
Druck: 1009 mb
Wind: 5 mph NNW
Windböe: 9 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 52%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:44 am
Sonnenuntergang: 9:14 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
9° | 11°°C 0.5 mm 50% 12 mph 90 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 19°°C 0.03 mm 3% 9 mph 87 % 1022 mb 0 mm/h
Di. Juni 10 10:00 pm
Wetter-Symbol
13° | 21°°C 0.33 mm 33% 9 mph 85 % 1020 mb 0 mm/h
Mi. Juni 11 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 9 mph 92 % 1020 mb 0 mm/h
Do. Juni 12 10:00 pm
Wetter-Symbol
18° | 26°°C 1 mm 100% 13 mph 93 % 1012 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
9° | 10°°C 0 mm 0% 10 mph 90 % 1010 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
10° | 11°°C 0 mm 0% 10 mph 81 % 1013 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 12 mph 53 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 12 mph 44 % 1019 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 51 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 15°°C 0.48 mm 48% 10 mph 74 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0.5 mm 50% 8 mph 80 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0.03 mm 3% 7 mph 81 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,650.37
1.21%
Ethereum(ETH)
€2,214.90
1.87%
Fesseln(USDT)
€0.88
-0.02%
XRP(XRP)
€1.91
0.71%
Solana(SOL)
€131.58
1.41%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.162276
3.32%
Shiba Inu(SHIB)
€0.000011
2.34%
Pepe(PEPE)
€0.000011
3.90%
Peanut das Eichhörnchen(PNUT)
€0.234364
7.64%
Nach oben scrollen