CISA Adds Four Actively Exploited Vulnerabilities to KEV
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Affected products include Cisco Catalyst SD‑WAN, multiple Qualcomm chipsets, and Broadcom VMware Aria Operations.
CVSS 10 CRITICAL: a vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco… EPSS 88% (100th percentile).
CISA federal remediation date Feb 27 · date passed
CVSS 7.8 HIGH: a vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated… EPSS 12% (96th percentile), up from 0.4%.
CISA federal remediation date Feb 27 · date passed
CISA warns of actively exploited Ivanti EPM and Cisco SD-WAN flaws
Patched vulnerabilities in Ivanti Endpoint Manager and Cisco Catalyst SD-WAN are under attack, according to the US security agency, which added reporting requirements to its previous Cisco directive.