Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the current snapshot and ordered by catalog date and CASCA priority.

Evidence current through Aug 27, 2026, 6:09 PM UTC
CISA KEV catalog boundaryCatalog silence leaves exploitation status unassessed. Alternate serialization never counts as a second source.1,677 catalog members · showing 1251–1300
1251
CVE-2013-5065CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Kernel Privilege Escalation Vulnerability

Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
74.876.1
Coverage
96%
1252
CVE-2010-0232CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Kernel Exception Handler Vulnerability

The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
74.575.6
Coverage
97%
1253
CVE-2017-11292CISA KEVSource-reported scopeEvidence supported

Adobe Flash Player Type Confusion Vulnerability

Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
74.675.4
Coverage
98%
1254
CVE-2017-6740CISA KEVSource-reported scopeEvidence supported

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
72.174.3
Coverage
94%
1255
CVE-2017-6738CISA KEVSource-reported scopeEvidence supported

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
72.074.3
Coverage
94%
1256
CVE-2017-6743CISA KEVSource-reported scopeEvidence supported

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
72.074.3
Coverage
94%
1257
CVE-2017-6739CISA KEVSource-reported scopeEvidence supported

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
72.073.3
Coverage
96%
1258
CVE-2018-8581CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Exchange Server Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
71.673.1
Coverage
97%
1259
CVE-2017-6744CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6.

CiscoIOS software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
70.072.6
Coverage
100%
1260
CVE-2018-0172CISA KEVSource-reported scopeEvidence supported

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
70.671.9
Coverage
97%
1261
CVE-2018-0155CISA KEVSource-reported scopeEvidence supported

Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.

CiscoCatalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
70.671.9
Coverage
97%
1262
CVE-2018-0173CISA KEVSource-reported scopeEvidence supported

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
70.671.8
Coverage
98%
1263
CVE-2018-0174CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

CiscoIOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
70.671.8
Coverage
98%
1264
CVE-2018-0158CISA KEVSource-reported scopeEvidence supported

Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

CiscoIOS Software and Cisco IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
70.471.7
Coverage
100%
1265
CVE-2008-3431CISA KEVSource-reported scopeEvidence supported

Oracle VirtualBox Insufficient Input Validation Vulnerability

An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.

OracleVirtualBox

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
69.971.5
Coverage
93%
1266
CVE-2013-1675CISA KEVSource-reported scopeEvidence supported

Mozilla Firefox Information Disclosure Vulnerability

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

MozillaFirefox

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
70.771.1
Coverage
100%
1267
CVE-2018-0167CISA KEVSource-reported scopeEvidence supported

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.

CiscoIOS, XR, and XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
69.871.0
Coverage
99%
1268
CVE-2017-0001CISA KEVSource-reported scopeEvidence supported

Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges

MicrosoftGraphics Device Interface (GDI)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
69.470.2
Coverage
99%
1269
CVE-2004-0210CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Privilege Escalation Vulnerability

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
69.070.2
Coverage
98%
1270
CVE-2009-1123CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Improper Input Validation Vulnerability

The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
69.070.0
Coverage
98%
1271
CVE-2015-4902CISA KEVSource-reported scopeEvidence supported

Oracle Java SE Integrity Check Vulnerability

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

OracleJava SE

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
69.169.5
Coverage
100%
1272
CVE-2018-0156CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.

CiscoIOS Software and Cisco IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
68.069.3
Coverage
97%
1273
CVE-2018-0175CISA KEVSource-reported scopeEvidence supported

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

CiscoIOS, XR, and XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
67.969.0
Coverage
99%
1274
CVE-2017-12237CISA KEVSource-reported scopeEvidence supported

Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
67.668.9
Coverage
95%
1275
CVE-2018-0159CISA KEVSource-reported scopeEvidence supported

Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

CiscoIOS Software and Cisco IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
67.568.8
Coverage
95%
1276
CVE-2002-0367CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Privilege Escalation Vulnerability

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
67.568.7
Coverage
96%
1277
CVE-2017-6627CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
67.268.5
Coverage
100%
1278
CVE-2020-11899CISA KEVSource-reported scopeEvidence supported

Treck TCP/IP stack Out-of-Bounds Read Vulnerability

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

Treck TCP/IP stackIPv6

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
67.468.3
Coverage
97%
1279
CVE-2017-12231CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

CiscoIOS software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
66.768.3
Coverage
93%
1280
CVE-2017-12233CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoIOS software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
66.768.3
Coverage
93%
1281
CVE-2017-12234CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoIOS software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
66.768.3
Coverage
93%
1282
CVE-2017-12235CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

CiscoIOS software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
66.768.3
Coverage
93%
1283
CVE-2018-0154CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.

CiscoIOS Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
66.768.3
Coverage
93%
1284
CVE-2016-8562CISA KEVSource-reported scopeEvidence supported

Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.

SiemensSIMATIC CP

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
66.167.4
Coverage
95%
1285
CVE-2018-0179CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CiscoIOS Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
61.865.6
Coverage
98%
1286
CVE-2018-0180CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CiscoIOS Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
61.865.6
Coverage
98%
1287
CVE-2018-0161CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software Resource Management Errors Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

CiscoIOS Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-17
Priority interval
62.764.3
Coverage
93%
1288
CVE-2017-12319CISA KEVSource-reported scopeEvidence supported

Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

CiscoIOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
62.964.2
Coverage
95%
1289
CVE-2017-6663CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
62.764.0
Coverage
100%
1290
CVE-2017-12232CISA KEVSource-reported scopeEvidence supported

Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.

CiscoIOS software

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
61.863.4
Coverage
93%
1291
CVE-2017-12238CISA KEVSource-reported scopeEvidence supported

Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

CiscoCatalyst 6800 Series Switches

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-03-03
Due
2022-03-24
Priority interval
61.763.3
Coverage
93%
1292
CVE-2014-6352CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Code Injection Vulnerability

Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-25
Due
2022-08-25
Priority interval
83.083.9
Coverage
99%
1293
CVE-2017-8570CISA KEVSource-reported scopeEvidence supported

Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-25
Due
2022-08-25
Priority interval
81.182.6
Coverage
98%
1294
CVE-2022-24682CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

SynacorZimbra Collaborate Suite (ZCS)

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-25
Due
2022-03-11
Priority interval
66.478.9
Coverage
85%
1295
CVE-2017-0222CISA KEVSource-reported scopeEvidence supported

Microsoft Internet Explorer Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-25
Due
2022-08-25
Priority interval
75.577.1
Coverage
95%
1296
CVE-2022-23131CISA KEVSource-reported scopeEvidence supported

Zabbix Frontend Authentication Bypass Vulnerability

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

ZabbixFrontend

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-22
Due
2022-03-08
Priority interval
85.088.2
Coverage
95%
1297
CVE-2022-23134CISA KEVAssessments differAssessments differSource-reported scope

Zabbix Frontend Improper Access Control Vulnerability

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

ZabbixFrontend

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-22
Due
2022-03-08
Priority interval
72.977.8
Coverage
86%
1298
CVE-2017-9841CISA KEVSource-reported scopeEvidence supported

PHPUnit Command Injection Vulnerability

PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

PHPUnitPHPUnit

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-15
Due
2022-08-15
Priority interval
88.789.8
Coverage
96%
1299
CVE-2022-24086CISA KEVSource-reported scopeEvidence supported

Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.

AdobeCommerce and Magento Open Source

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-15
Due
2022-03-01
Priority interval
87.989.2
Coverage
99%
1300
CVE-2018-8174CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"

MicrosoftWindows

Required actionApply updates per vendor instructions.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2022-02-15
Due
2022-08-15
Priority interval
83.988.2
Coverage
93%