CISA Adds 6 Vulnerabilities: Apple Also on Attack List

CISA Adds 6 Vulnerabilities: Apple Also on Attack List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

This includes a high-severity security vulnerability, CVE-2023-27524 (CVSS score: 8.9), affecting Apache Superset, an open-source data visualization software, allowing remote code execution. The details of this issue first surfaced in April 2023, described by Naveen Sunkavally from Horizon3.ai as “a dangerous default configuration in Apache Superset that allows an unauthenticated attacker to execute remote code, gather credentials, and jeopardize data.”

Currently, it is unknown how this security vulnerability is being exploited. Additionally, CISA has added five more flaws:

• CVE-2023-38203 (CVSS score: 9.8) – Insecure Deserialization Vulnerability in Adobe ColdFusion

• CVE-2023-29300 (CVSS score: 9.8) – Insecure Deserialization Vulnerability in Adobe ColdFusion

• CVE-2023-41990 (CVSS score: 7.8) – Multiple Product Code Execution Vulnerability in Apple

• CVE-2016-20017 (CVSS score: 9.8) – Command Injection Vulnerability in D-Link DSL-2750B Devices

• CVE-2023-23752 (CVSS score: 5.3) – Inappropriate Access Control Vulnerability in Joomla!

CVE-2023-41990, patched by Apple in iOS 15.7.8 and iOS 16.3, is being used by unknown actors as part of Triada Operation spyware attacks to enable remote code execution while processing a specially crafted iMessage PDF attachment.

The Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes for the above-mentioned vulnerabilities by January 29, 2024, to protect their networks against active threats.

Hackdra
@hackdra Cybersecurity

Hackdra was founded in 2019 by of the sector Pioneer cyber defense experts determined to save the internet from cyber deteriorations. By combining his passion for security with the high-level artificial intelligence technology he developed, he earned the title of the industry’s “first and only Dynamic Artificial Intelligence-based cybersecurity company”. By developing innovative methods for security risks that traditional methods cannot prevent, it has gave direction the understanding of security in the sector and has made a name for itself in the world cyber security configurations.

Related Posts