Kwetsbaarheden - Week 38

Het CSIRT-DSP maakt op wekelijkse basis een selectie van kwetsbaarheden, waarbij het CSIRT-DSP de inschatting heeft gemaakt dat deze relevant zijn voor digitale dienstverleners.

Het betreft een selectie van 'Medium' en 'High' kwetsbaarheden. Voor de inschatting hiervan wordt er gebruik gemaakt van de CVSS 3.1 base scores indien deze beschikbaar zijn. Indien deze niet beschikbaar zijn, zal dit worden aangegeven met 'n/a'.

Critical & High

Forgerock LDAP connector

https://nvd.nist.gov/vuln/detail/CVE-2022-0143 (9.3)

HPE Integrated Lights-Out 5 (iLO)

https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf04365en_us (8.5-5.0)

Trend Micro Apex One

https://success.trendmicro.com/dcx/s/solution/000291528 (8.2-5.5)

Watchdog Anti-Virus

https://nvd.nist.gov/vuln/detail/CVE-2022-38611 (7.8)

Microsoft Endpoint Configuration Manager

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37972 (7.5)

Nextcloud server

https://nvd.nist.gov/vuln/detail/CVE-2022-36074 (7.5)

Kubernetes

https://groups.google.com/g/kubernetes-security-announce/c/qqTZgulISzA (n/a)

Tinyproxy

https://nvd.nist.gov/vuln/detail/CVE-2022-40468 (n/a)

Medium

Grafana

https://nvd.nist.gov/vuln/detail/CVE-2022-35957 (6.6)

https://github.com/grafana/grafana/security/advisories/GHSA-p978-56hq-r492 (6.4)

KubeVirt

https://nvd.nist.gov/vuln/detail/CVE-2022-1798 (6.5)

OpenAM Consortium Edition

https://nvd.nist.gov/vuln/detail/CVE-2022-31735 (6.1)

Cisco IOS XR Software

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-bng-Gmg5Gxt (6.1)

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xr-cdp-wnALzvT2 (4.3)

SFTPGo

https://nvd.nist.gov/vuln/detail/CVE-2022-39220 (6.1)

Cisco Network Convergence System 4000 Series

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ncs4k-tl1-GNnLwC6 (6.0)

IBM Spectrum Protect Plus

https://nvd.nist.gov/vuln/detail/CVE-2022-40608 (5.9)

Zyxel GS1900

https://nvd.nist.gov/vuln/detail/CVE-2022-34746 (5.9)

Trend Micro Apex One

https://nvd.nist.gov/vuln/detail/CVE-2022-40141 (5.6)

https://nvd.nist.gov/vuln/detail/CVE-2022-40140 (5.5)

Palo Alto Networks Cortex XDR agent

https://nvd.nist.gov/vuln/detail/CVE-2022-0029 (5.5)

Kubernetes

https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak (5.1)

HPE Integrated Lights-Out 5 (iLO 5)

https://nvd.nist.gov/vuln/detail/CVE-2022-28637 (5.0)

Nextcloud Files Access Control

https://nvd.nist.gov/vuln/detail/CVE-2022-36075 (4.3)

Nextcloud Talk

https://nvd.nist.gov/vuln/detail/CVE-2022-39212 (4.3)

Zoho ManageEngine Password Manager Pro, PAM360, Access Manager Plus

https://nvd.nist.gov/vuln/detail/CVE-2022-40300 (n/a)