Kwetsbaarheden - Week 27

Het CSIRT-DSP maakt op wekelijkse basis een selectie van kwetsbaarheden, waarbij het CSIRT-DSP de inschatting heeft gemaakt dat deze relevant zijn voor digitale dienstverleners.

Het betreft een selectie van 'Medium' en 'High' kwetsbaarheden. Voor de inschatting hiervan wordt er gebruik gemaakt van de CVSS 3.1 base scores indien deze beschikbaar zijn. Indien deze niet beschikbaar zijn, zal dit worden aangegeven met 'n/a'.

Critical & High

Gitlab CE/EE

https://nvd.nist.gov/vuln/detail/CVE-2022-2185 (9.9)

https://nvd.nist.gov/vuln/detail/CVE-2022-2235 (8.7)

https://nvd.nist.gov/vuln/detail/CVE-2022-2230 (8.1)

https://nvd.nist.gov/vuln/detail/CVE-2022-2229 (7.5)

Fortinet FortiNAC

https://fortiguard.fortinet.com/psirt/FG-IR-22-058 (8.0)

Fortinet FortiDeceptor

https://fortiguard.fortinet.com/psirt/FG-IR-21-213 (7.9)

Fortinet FortiClient (Windows)

https://fortiguard.fortinet.com/psirt/FG-IR-21-190 (7.8)

Fortinet FortiAnalyzer / FortiManager / FortiOS / FortiProxy

https://fortiguard.fortinet.com/psirt/FG-IR-21-206 (7.4)

Elastics Endpoint Security (Windows)

https://discuss.elastic.co/t/elastic-8-3-1-8-3-0-and-7-17-5-security-update/308613 (7.0)

Devolutions Server

https://devolutions.net/security/advisories/DEVO-2022-0006 (n/a)

Jira Datacenter / Server (Mobile Plugin)

https://nvd.nist.gov/vuln/detail/CVE-2022-26135 (n/a)

OpenSSL

https://nvd.nist.gov/vuln/detail/CVE-2022-2274 (n/a)

Xen Project

https://nvd.nist.gov/vuln/detail/CVE-2022-33743 (n/a)

Zoho ManageEngine ServiceDesk Plus MSP

https://nvd.nist.gov/vuln/detail/CVE-2022-32551 (n/a)

Medium

Fortinet FortiManager / FortiAnalyzer

https://fortiguard.fortinet.com/psirt/FG-IR-22-049 (6.8)

https://fortiguard.fortinet.com/psirt/FG-IR-21-056 (6.5)

Gitlab CE/EE

https://nvd.nist.gov/vuln/detail/CVE-2022-1983 (6.5)

https://nvd.nist.gov/vuln/detail/CVE-2022-1981 (5.9)

https://nvd.nist.gov/vuln/detail/CVE-2022-1963 (5.3)

https://nvd.nist.gov/vuln/detail/CVE-2022-2228 (5.3)

https://nvd.nist.gov/vuln/detail/CVE-2022-2243 (5.0)

https://nvd.nist.gov/vuln/detail/CVE-2022-2250 (4.7)

https://nvd.nist.gov/vuln/detail/CVE-2022-2244 (4.3)

https://nvd.nist.gov/vuln/detail/CVE-2022-1954 (4.3)

https://nvd.nist.gov/vuln/detail/CVE-2022-2227 (4.3)

Elastic Kibana

https://discuss.elastic.co/t/elastic-8-3-1-8-3-0-and-7-17-5-security-update/308613 (6.4)

Fortinet FortiOS / FortiProxy

https://fortiguard.fortinet.com/psirt/FG-IR-21-179 (6.3)

https://fortiguard.fortinet.com/psirt/FG-IR-21-155 (4.2)

Nextcloud Server

https://nvd.nist.gov/vuln/detail/CVE-2022-31014 (5.4)

Fortinet FortiEDR

https://fortiguard.fortinet.com/psirt/FG-IR-22-077 (5.1)

Fortinet FortiADC

https://fortiguard.fortinet.com/psirt/FG-IR-22-051 (5.1)

Fortinet FortiSwitch / FortiRecorder / FortiVoiceEnterprise

https://fortiguard.fortinet.com/psirt/FG-IR-21-155 (4.2)

GnuPG

https://nvd.nist.gov/vuln/detail/CVE-2022-34903 (n/a)

OpenSSL

https://nvd.nist.gov/vuln/detail/CVE-2022-2097 (n/a)

Xen Project

https://nvd.nist.gov/vuln/detail/CVE-2022-26365 (n/a)

https://nvd.nist.gov/vuln/detail/CVE-2022-33740 (n/a)

https://nvd.nist.gov/vuln/detail/CVE-2022-33741 (n/a)

https://nvd.nist.gov/vuln/detail/CVE-2022-33742 (n/a)

https://nvd.nist.gov/vuln/detail/CVE-2022-33744 (n/a)

Zoho ManageEngine ADSelfService Plus

https://nvd.nist.gov/vuln/detail/CVE-2022-34829 (n/a)