The US Cybersecurity and Infrastructure Security Agency (CISA) maintains a list of known vulnerabilities that are the most commonly exploited by threat actors. At the start of March the list was extended by another 95 bugs including several critical Cisco vulnerabilities.
The known exploited vulnerabilities catlog is part of the CISA’s Shields-Up initiative that provides guidance for security managers and network defenders.
The 95 vulnerabilities added to the list of commonly exploited security bugs in March include:
- Critical vulnerabilities in Cisco RV series routers allowing arbitrary command execution with elevated privilege (CVE-2022-20708, CVE-2022-20703, CVE-2022-20701, CVE-2022-20700 and CVE-2022-20699)
- Among the 27 Windows vulnerabilities added is a privilege escalation vulnerability in the Windows Installer used in attacks in November (CVE-2021-41379) and many older vulnerabilities up to 20 years old which are still being exploited.
- A remote code execution vulnerability in the Exim email server (CVE-2019-16928)
Of the 95 vulnerabilities added to the known exploits list this month, only 13 were published this year and the rest are all older – which underlines the importance of promptly installing security patches each month and not ignoring older vulnerabilities if they remain unpatched on your network.
“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”
Aim Ltd Chief Technology Officer (CTO)