Kwetsbaarheden - Week 21

Het CSIRT-DSP maakt op wekelijkse basis een selectie van kwetsbaarheden, waarbij het CSIRT-DSP de inschatting heeft gemaakt dat deze relevant zijn voor digitale dienstverleners.

Het betreft een selectie van 'Medium' en 'High' kwetsbaarheden. Voor de inschatting hiervan wordt er gebruik gemaakt van de CVSS 3.1 base scores indien deze beschikbaar zijn. Indien deze niet beschikbaar zijn, zal dit worden aangegeven met 'n/a'.

Critical & High

VMware Workspace ONE Access / Identity Manager

https://nvd.nist.gov/vuln/detail/CVE-2022-22972 (9.8)

https://nvd.nist.gov/vuln/detail/CVE-2022-22973 (7.8)

Spring Security

https://nvd.nist.gov/vuln/detail/CVE-2022-22978 (8.2)

Zyxel USG FLEX / ATP / VPN / NSG

https://nvd.nist.gov/vuln/detail/CVE-2022-26532 (7.8)

Acronis Cyber Protect

https://nvd.nist.gov/vuln/detail/CVE-2022-30994 (7.5)

BIND

https://nvd.nist.gov/vuln/detail/CVE-2022-1183 (7.5)

Grafana Enterprise Logs

https://nvd.nist.gov/vuln/detail/CVE-2022-28660 (n/a)

Zoho ManageEngine ADSelfService Plus

https://nvd.nist.gov/vuln/detail/CVE-2022-28987 (n/a)

Medium

Grafana Enterprise

https://nvd.nist.gov/vuln/detail/CVE-2022-29170 (6.6)

Cisco IOS XR Health Check

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-redis-ABJyE5xK (6.5)

Zyxel USG FLEX / ATP / VPN

https://nvd.nist.gov/vuln/detail/CVE-2022-0910 (6.5)

https://nvd.nist.gov/vuln/detail/CVE-2022-26531 (6.1)

https://nvd.nist.gov/vuln/detail/CVE-2022-0734 (5.8)

Cisco Common Services Platform Collector

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-multi-xss-tyDFjhwb (6.1)

Zyxel NSG

https://nvd.nist.gov/vuln/detail/CVE-2022-26531 (6.1)

VMWare Tools (Windows)

https://nvd.nist.gov/vuln/detail/CVE-2022-22977 (5.8)

Acronis Cyber Protect (Windows / Linux)

https://nvd.nist.gov/vuln/detail/CVE-2022-30993 (5.7)

Cisco Expressway Series  / TelePresence Video Communication Server

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-bsFVwueV (5.5-4.3)

Cisco Secure Network Analytics

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-stealth-rce-2hYb9KFK (5.5)

Cisco Enterprise Chat and Email Stored

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-strd-xss-BqFXO9D2 (5.4)

Spring Security

https://nvd.nist.gov/vuln/detail/CVE-2022-22976 (5.3)



Nextcloud Deck

https://nvd.nist.gov/vuln/detail/CVE-2022-29159 (5.0)

Cisco UCS Director

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-UCS-XSS-uQSME3L7 (4.8)