28. 03. 2024 Mirko Ioris SOCnews

SOC News | Mar 28 – New Vulnerabilities Added to the KEV Catalog

On March 25, 2024, the Cybersecurity & Infrastructure Security Agency (CISA) added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The catalog is updated regularly and contains those vulnerabilities most likely to be used in attacks. Organizations should monitor and review it periodically, and prioritize their patching efforts based on it.

I’ll provide a summary of the most critical vulnerabilities here:

CVE NumberCVSS ScoreEPSS ScoreProduct
CVE-2023-487889.8 (Critical)Not availableIvanti (EPM CSA)
CVE-2021-445299.8 (Critical)96.89% (Critical)Fortinet FortiClient
CVE-2019-725610.0 (Critical)99.95%(Critical)Linear eMerge E3-Series
Details of the vulnerabilities

The most dangerous one is the CVE-2019-7256, a critical command injection vulnerability found in Nice Linear devices five years ago. With it an attacker could potentially take complete control of the affected system by sending malicious code. If you’re using a Nice Linear eMerge E3-Series device you should update the firmware immediately.

Mirko Ioris

Mirko Ioris

Technical Consultant - Cyber Security Team | Würth Phoenix

Author

Mirko Ioris

Technical Consultant - Cyber Security Team | Würth Phoenix

Leave a Reply

Your email address will not be published. Required fields are marked *

Archive