Eyeon Security Information security company

보안 권고문

㈜아이온시큐리티에서 서비스 이용 고객님들의 안정적인 시스템 운영을 위해
필수적인 주요 보안 조치 사항을 안내해드립니다.

현재 악용되고 있는 Exploit(Update. 2023-09-18) 관리자 2023-09-20 05:37:51
현재 악용되고 있는 Exploit(Update. 2023-09-18)
관리자  2023-09-20 05:37:51

현재 자주 악용되고 있는 취약점 목록으로, 취약한 버전의 SW를 사용 중인 경우 긴급 패치를 권고 드립니다.
* 참조 링크 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog


cveIDvendorProjectvulnerabilityNamedateAddedshortDescriptionrequiredActiondueDate
CVE-2022-31463Owl LabsOwl Labs Meeting Owl Improper Authentication Vulnerability2023-09-18Owl Labs Meeting Owl contains an improper authentication vulnerability that does not require a password for Bluetooth commands, as only client-side authentication is used.Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.2023-10-09
CVE-2022-31462Owl LabsOwl Labs Meeting Owl Use of Hard-coded Credentials Vulnerability2023-09-18Owl Labs Meeting Owl contains a use of hard-coded credentials vulnerability that allows an attacker to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.2023-10-09
CVE-2022-31461Owl LabsOwl Labs Meeting Owl Missing Authentication for Critical Function Vulnerability2023-09-18Owl Labs Meeting Owl contains a missing authentication for critical functions vulnerability that allows an attacker to deactivate the passcode protection mechanism via a certain c 11 message.Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.2023-10-09
CVE-2022-31459Owl LabsOwl Labs Meeting Owl Inadequate Encryption Strength Vulnerability2023-09-18Owl Labs Meeting Owl contains an inadequate encryption strength vulnerability that allows an attacker to retrieve the passcode hash via a certain c 10 value over Bluetooth.Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.2023-10-09
CVE-2021-3129LaravelLaravel Ignition File Upload Vulnerability2023-09-18Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.2023-10-09
CVE-2017-6884ZyxelZyxel EMG2926 Routers Command Injection Vulnerability2023-09-18Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.2023-10-09
CVE-2014-8361RealtekRealtek SDK Improper Input Validation Vulnerability2023-09-18Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.2023-10-09
CVE-2022-22265SamsungSamsung Mobile Devices Use-After-Free Vulnerability2023-09-18Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

2023-10-09





출처 사이트 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog


첨부 파일 :