Site icon TheCyberThrone

CISA Catalog Update-June 25, 2025

Advertisements

πŸ” Executive Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent update to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting three newly confirmed exploited security flaws affecting:

These additions represent active threats across infrastructure, IoT, and perimeter defense ecosystems. Under Binding Operational Directive (BOD) 22-01, federal civilian executive branch (FCEB) agencies are required to patch or mitigate these vulnerabilities by assigned deadlines, while all other organizations are strongly encouraged to do the same.

🧩 1. CVE-2024-54085 – AMI MegaRAC SPx BMC Authentication Bypass

πŸ”Ž BMC exploitation enables persistent backdoor access below the operating system level β€” often invisible to endpoint detection tools.

🌐 2. CVE-2024-0769 – D-Link DIR-859 Path Traversal Vulnerability

πŸ”Ž Path traversal flaws in embedded devices can be chained with command injection vulnerabilities or privilege misuse.

πŸ” 3. CVE-2019-6693 – Fortinet FortiOS Hard-Coded Credentials

πŸ”Ž Hard-coded credentials remain one of the top methods of perimeter breaches in unmanaged or neglected network appliances.

βœ… Remediation Guidance & Recommended Actions

πŸ”„ Immediate Steps

πŸ” Long-Term Security Hardening

Exit mobile version