8월 29일 일일 보안현황
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.
보안 뉴스, CVE, 제품명, KISA 공지와 브리핑을 한 번에 검색합니다.
하루 뒤 PTC가 침해지표(IoC)를 공개하면서 실제 악용 사례가 확인됐다고 시큐리티위크는 전했습니다. 이 취약점은 6월 말 CISA 알려진 악용 취약점(KEV) 목록에도 올랐습니다.
8일(현지시간) 블록체인 매체 디크립트에 따르면 이 조직은 지갑, 암호 라이브러리, 인프라 등 비트코인 핵심 소프트웨어 전반을 대상으로 AI 기반 보안 감사를 진행하고 있습니다. 레드팀은 공격자 관점에서 소프트웨어를 시험해 실제 악용 전에 취약점을 찾아내는 보안 인력을 뜻합니다.
미국 국토안보부 외교안보국 산하 사이버보안·인프라보안국(CISA)이 디바이스 서버 랜트로닉스(Lantronix) EDS5000 시리즈의 치명적인 취약점이 현재 실제 공격에 악용되고 있다고 경고했습니다.
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vuln...
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net dom...
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 a...
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier
Microsoft Exchange Server Remote Code Execution Vulnerability
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 2건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 1건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 2건을 먼저 다룹니다.
오늘은 실제 악용이 확인됐거나 공식 영향 범위가 바뀐 이슈 3건을 먼저 다룹니다.
공개 시점이 아니라 실제 악용·공식 확인·공격 조건·수정 기준을 근거로 중요한 변화 3건을 선별했습니다.
최근 7일 CISA KEV 신규 등록은 9건으로, 직전 7건보다 2건(28.6%) 증가했습니다. 실제 악용 확인 항목이 늘어 KEV 대상 자산의 조치 우선순위를 높여야 합니다. 전체 신규 CVE 중 긴급·높음 비중은 48.4%로 직전 49.9%보다 1.5%p 하락했습니다.
최근 7일 CISA KEV 신규 등록은 9건으로, 직전 4건보다 5건(125.0%) 증가했습니다. 실제 악용 확인 항목이 늘어 KEV 대상 자산의 조치 우선순위를 높여야 합니다. 전체 신규 CVE 중 긴급·높음 비중은 58.0%로 직전 51.2%보다 6.8%p 상승했습니다.