Site icon TheCyberThrone

CISA KEV Catalog Update Part I – March 2025

Advertisements

On March 3, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog by adding several new vulnerabilities, including those affecting Hitachi Vantara and other products. Here are the details of the newly added vulnerabilities:

CVE-2023-20118 – Cisco Small Business RV Series Routers Command Injection Vulnerability

CVE-2022-43939 – Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

CVE-2022-43769 – Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

CVE-2018-8639 – Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

CVE-2024-4885 – Progress WhatsUp Gold Path Traversal Vulnerability

These vulnerabilities have been added to the KEV catalog based on evidence of active exploitation, highlighting the importance of timely patching and mitigation to protect against potential attacks.

For more detailed information, you can refer to the CISA Known Exploited Vulnerabilities Catalog.

Exit mobile version