Home > 취약점 정보 공유 > 보안공지
보안공지

목록

조회수 : 537


美 CISA 발표 주요 Exploit 정보공유(Update. 2025-05-01)2025-05-01
현재 자주 악용되고 있는 취약점 목록으로, 취약한 버전의 SW를 사용 중인 경우 긴급 패치를 권고 드립니다.
* 참조 링크 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog

cveIDvendorProjectvulnerabilityNamedateAddedshortDescriptionrequiredActiondueDate
CVE-2023-44221SonicWallSonicWall SMA100 Appliances OS Command Injection Vulnerability2025-05-01SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-05-22
CVE-2024-38475ApacheApache HTTP Server Improper Escaping of Output Vulnerability2025-05-01Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-05-22
출처 사이트 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog