Skip to content

Commit ee78d37

Browse files
Update KEV: Thu Dec 19 00:12:05 UTC 2024
Signed-off-by: AboutCode Automation <[email protected]>
1 parent cfee9f6 commit ee78d37

File tree

1 file changed

+63
-3
lines changed

1 file changed

+63
-3
lines changed

known_exploited_vulnerabilities.json

Lines changed: 63 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,69 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2024.12.17",
4-
"dateReleased": "2024-12-17T15:01:47.8969Z",
5-
"count": 1232,
3+
"catalogVersion": "2024.12.18",
4+
"dateReleased": "2024-12-18T17:28:24.7207Z",
5+
"count": 1236,
66
"vulnerabilities": [
7+
{
8+
"cveID": "CVE-2021-40407",
9+
"vendorProject": "Reolink",
10+
"product": "RLC-410W IP Camera",
11+
"vulnerabilityName": "Reolink RLC-410W IP Camera OS Command Injection Vulnerability ",
12+
"dateAdded": "2024-12-18",
13+
"shortDescription": "Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.",
14+
"requiredAction": "The impacted product could be end-of-life (EoL) and\/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
15+
"dueDate": "2025-01-08",
16+
"knownRansomwareCampaignUse": "Unknown",
17+
"notes": "https:\/\/reolink.com\/product-eol\/ ; https:\/\/reolink.com\/download-center\/ ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-40407",
18+
"cwes": [
19+
"CWE-78"
20+
]
21+
},
22+
{
23+
"cveID": "CVE-2019-11001",
24+
"vendorProject": "Reolink",
25+
"product": "Multiple IP Cameras",
26+
"vulnerabilityName": "Reolink Multiple IP Cameras OS Command Injection Vulnerability",
27+
"dateAdded": "2024-12-18",
28+
"shortDescription": "Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the \"TestEmail\" functionality to inject and run OS commands as root.",
29+
"requiredAction": "The impacted product could be end-of-life (EoL) and\/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
30+
"dueDate": "2025-01-08",
31+
"knownRansomwareCampaignUse": "Unknown",
32+
"notes": "https:\/\/reolink.com\/product-eol\/ ; https:\/\/reolink.com\/download-center\/ ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-11001",
33+
"cwes": [
34+
"CWE-78"
35+
]
36+
},
37+
{
38+
"cveID": "CVE-2022-23227",
39+
"vendorProject": "NUUO",
40+
"product": "NVRmini2 Devices",
41+
"vulnerabilityName": "NUUO NVRmini 2 Devices Missing Authentication Vulnerability ",
42+
"dateAdded": "2024-12-18",
43+
"shortDescription": "NUUO NVRmini 2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. ",
44+
"requiredAction": "The impacted product is end-of-life (EoL) and\/or end-of-service (EoS). Users should discontinue utilization of the product.",
45+
"dueDate": "2025-01-08",
46+
"knownRansomwareCampaignUse": "Unknown",
47+
"notes": "https:\/\/nuuo.com\/wp-content\/uploads\/2023\/03\/NUUO-EOL-letter\uff3fNVRmini-2-and-NVRsolo-series.pdf ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23227",
48+
"cwes": [
49+
"CWE-306"
50+
]
51+
},
52+
{
53+
"cveID": "CVE-2018-14933",
54+
"vendorProject": "NUUO",
55+
"product": "NVRmini Devices",
56+
"vulnerabilityName": "NUUO NVRmini Devices OS Command Injection Vulnerability ",
57+
"dateAdded": "2024-12-18",
58+
"shortDescription": "NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.",
59+
"requiredAction": "The impacted product is end-of-life (EoL) and\/or end-of-service (EoS). Users should discontinue utilization of the product.",
60+
"dueDate": "2025-01-08",
61+
"knownRansomwareCampaignUse": "Unknown",
62+
"notes": "https:\/\/nuuo.com\/wp-content\/uploads\/2023\/03\/NUUO-EOL-letter\uff3fNVRmini-2-and-NVRsolo-series.pdf ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-14933",
63+
"cwes": [
64+
"CWE-78"
65+
]
66+
},
767
{
868
"cveID": "CVE-2024-55956",
969
"vendorProject": "Cleo",

0 commit comments

Comments
 (0)