Weekly digest
Week 6, 2023 (6–12 Feb)
8 new CVEs this week, in line with the recent average. Severity skewed high: 5 high, 63% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2023-0669High· 7.2CISA KEVPoCFortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in versi…
CVE-2015-2291High· 7.8CISA KEVPoC(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted …
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted …
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2023-0669High· 7.2CISA KEVPoCFortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in versi…
CVE-2023-0286High· 7.4openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…
CVE-2023-25307High· 8.8mrpack-install vulnerable to path traversal with dependency
mrpack-install vulnerable to path traversal with dependency
CVE-2023-23631High· 7.5IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics
IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics
GHSA-74fp-r6jw-h4mpHigh· 7.5Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
CVE-2023-23931Medium· 6.5Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
CVE-2023-23626Medium· 5.9IPFS go-bitfield vulnerable to DoS via malformed size arguments
IPFS go-bitfield vulnerable to DoS via malformed size arguments
CVE-2023-24816Medium· 4.5IPython vulnerable to command injection via set_term_title
IPython vulnerable to command injection via set_term_title
Most-affected vendors
By CVEs published in the period.