CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

CVE-2020-3259 Cisco ASA and FTD Information Disclosure Vulnerability
CVE-2024-21410 Microsoft Exchange Server Privilege Escalation Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.Â

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See theÂBOD 22-01 Fact Sheet for more information.

Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Ukrainian national pleads guilty for roles in Zeus, IcedID malware operations

February 15, 2024 0 Comments 0 tags

A Ukrainian man accused of playing key roles in two prolific malware groups that bilked millions from victims around the world over a decade pleaded guilty in a U.S. federal

Tech companies pledge to protect 2024 elections from AI-generated media

February 16, 2024 0 Comments 0 tags

A coalition of major technology companies committed on Friday to limit the malicious use of deepfakes and other forms of artificial intelligence to manipulate or deceive voters in democratic elections.

Half of IT Leaders Identify IoT as Security Weak Point

February 27, 2024 0 Comments 0 tags

The Viakoo study also said 50% firms faced IoT cyber incidents in past year, 44% of which were severe