Site icon TheCyberThrone

CISA Adds Two Vulnerabilities to KEV Catalog

Advertisements

The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities affecting Apache HTTP Server and SonicWall SMA100 appliances to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. These vulnerabilities pose significant risks to affected systems and require immediate remediation.

1. Apache HTTP Server Vulnerability (CVE-2024-38475)

Overview

2. SonicWall SMA100 Appliances Vulnerability (CVE-2023-44221)

Overview

3. Exploitation Details

Apache HTTP Server (CVE-2024-38475)

SonicWall SMA100 (CVE-2023-44221)

4. Mitigation Strategies

A. Apply Security Updates

B. Restrict Access

C. Monitor for Exploitation

5. Compliance Requirements

Federal Agencies

Under Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies must remediate these vulnerabilities by May 17, 2025.

Conclusion

The addition of CVE-2024-38475 (Apache HTTP Server) and CVE-2023-44221 (SonicWall SMA100) to the KEV Catalog highlights the urgency of patching affected systems. Organizations must prioritize updates and implement security controls to mitigate risks.

Exit mobile version