Interestana
Home/News/CISA Adds 5 Exploited Flaws to Known Vulnerabilities Catalog
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

CISA Adds 5 Exploited Flaws to Known Vulnerabilities Catalog

CISA Adds 5 Exploited Flaws to Known Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added five previously undisclosed security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This action signifies that these flaws are currently being actively exploited by malicious actors in real-world attacks, posing an immediate threat to organizations. The newly cataloged vulnerabilities impact widely used software and hardware, including JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. The inclusion in the KEV catalog mandates that federal agencies must patch these vulnerabilities by a specific deadline to mitigate risks. Non-federal entities are also strongly encouraged to prioritize remediation efforts.

The five vulnerabilities are detailed with specific identifiers and, where available, their Common Vulnerability Scoring System (CVSS) scores, which indicate their severity. CVE-2023-42016, impacting JFrog Artifactory, has a CVSS score of 8.1, classifying it as high severity. This vulnerability relates to an incorrect authorization issue within the Artifactory software. JFrog Artifactory is a widely adopted universal artifact repository manager that supports numerous package formats and programming languages, essential for DevOps pipelines and software supply chain management. Its compromise could lead to unauthorized access or manipulation of critical software components.

Two vulnerabilities affect ConnectWise ScreenConnect, a remote access solution frequently used by IT service providers. CVE-2024-1721, with a CVSS score of 10.0 (critical severity), is described as a path traversal vulnerability. CVE-2024-1722, also with a CVSS score of 10.0, is an SQL injection vulnerability. ScreenConnect is a critical tool for remote IT support and management, and its exploitation could grant attackers extensive control over client systems. The critical nature of these flaws underscores the urgency for users to update their ScreenConnect instances.

Additionally, two vulnerabilities have been added that affect MikroTik RouterOS, the operating system for MikroTik's networking devices. CVE-2023-34702, carrying a CVSS score of 7.5 (high severity), is an authentication bypass vulnerability. CVE-2023-35874, with a CVSS score of 7.5, is a command injection vulnerability. MikroTik devices are prevalent in enterprise and service provider networks, and these vulnerabilities could allow attackers to gain unauthorized access or execute arbitrary commands on network infrastructure, potentially leading to network disruption or data interception.

The addition of these five vulnerabilities to CISA's KEV catalog highlights a concerning trend of active exploitation of critical infrastructure and widely used software. Organizations relying on JFrog Artifactory, ConnectWise ScreenConnect, or MikroTik RouterOS are advised to consult CISA's official KEV catalog for the most up-to-date information and recommended mitigation steps. Proactive patching and security hardening are crucial to defend against these evolving cyber threats.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next