The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that threat actors have abused in attacks and that are required to be addressed by Federal Civilian Executive Branch (FCEB) agencies.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Known Exploited Vulnerabilities Catalog and address the vulnerabilities in their infrastructure.
The Cybersecurity and Infrastructure Security Agency (CISA) this week added seventeen actively exploited vulnerabilities to the Catalog.
The total number of vulnerabilities included in the catalog reached this week 341 vulnerabilities.
CISA is requiring 10 of 17 vulnerabilities added this week to be addressed within February 1st, 2022.
|CVE Number||CVE Title||Required Action Due Date|
|CVE-2021-32648||October CMS Improper Authentication||2/1/2022|
|CVE-2021-21315||System Information Library for node.js Command Injection Vulnerability||2/1/2022|
|CVE-2021-21975||Server Side Request Forgery in vRealize Operations Manager API Vulnerability||2/1/2022|
|CVE-2021-22991||BIG-IP Traffic Microkernel Buffer Overflow Vulnerability||2/1/2022|
|CVE-2021-25296||Nagios XI OS Command Injection Vulnerability||2/1/2022|
|CVE-2021-25297||Nagios XI OS Command Injection Vulnerability||2/1/2022|
|CVE-2021-25298||Nagios XI OS Command Injection Vulnerability||2/1/2022|
|CVE-2021-33766||Microsoft Exchange Server Information Disclosure Vulnerability||2/1/2022|
|CVE-2021-40870||Aviatrix Controller Unrestricted Upload of File Vulnerability||2/1/2022|
|CVE-2021-35247||SolarWinds Serv-U Improper Input Validation Vulnerability||02/04/2022|
|CVE-2020-11978||Apache Airflow Command Injection Vulnerability||7/18/2022|
|CVE-2020-13671||Drupal Core Unrestricted Upload of File Vulnerability||7/18/2022|
|CVE-2020-13927||Apache Airflow Experimental API Authentication Bypass Vulnerability||7/18/2022|
|CVE-2020-14864||Oracle Corporate Business Intelligence Enterprise Edition Path Traversal Vulnerability||7/18/2022|
|CVE-2006-1547||Apache Struts 1 ActionForm Denial of Service Vulnerability||07/21/2022|
|CVE-2012-0391||Apache Struts 2 Improper Input Validation Vulnerability||07/21/2022|
|CVE-2018-8453||Microsoft Windows Win32k Privilege Escalation Vulnerability||07/21/2022|
CISA also added a vulnerability, tracked as CVE-2021-35247, recently addressed by SolarWinds in Serv-U products that threat actors are actively exploited in the wild. The company pointed out that all the attack attempts failed.
(SecurityAffairs – hacking, Known Exploited Vulnerabilities Catalog)