Alerts: CISA Adds Two Known Exploited Vulnerabilities to Catalog

Source URL: https://www.cisa.gov/news-events/alerts/2025/01/13/cisa-adds-two-known-exploited-vulnerabilities-catalog
Source: Alerts
Title: CISA Adds Two Known Exploited Vulnerabilities to Catalog

Feedly Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

CVE-2024-12686 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
CVE-2024-48365 Qlik Sense HTTP Tunneling Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

AI Summary and Description: Yes

Summary: The text discusses the inclusion of two new vulnerabilities in CISA’s Known Exploited Vulnerabilities Catalog. These vulnerabilities highlight active risks within federal networks and emphasize the need for timely remediation by organizations, especially those within the Federal Civilian Executive Branch.

Detailed Description: This content is relevant to the Information Security category, as it outlines the proactive measures taken by CISA in response to known vulnerabilities that pose threats to cybersecurity. The discussion around CVEs and the Binding Operational Directive provides critical insights into government compliance and provides a framework for organizations to improve their security posture.

– **Vulnerabilities Added**:
– **CVE-2024-12686**: A command injection vulnerability in BeyondTrust’s Privileged Remote Access and Remote Support applications.
– **CVE-2024-48365**: An HTTP tunneling vulnerability in Qlik Sense.

– **Risk Assessment**: These vulnerabilities constitute frequent attack vectors exploited by malicious actors, underlining their significant risk to federal enterprise operations.

– **Binding Operational Directive (BOD) 22-01**:
– This directive mandates the remediation of identified vulnerabilities by set deadlines to safeguard federal networks.
– Establishes the Known Exploited Vulnerabilities Catalog as an evolving list of significant CVEs.

– **Recommendations**: Although primarily aimed at Federal Civilian Executive Branch (FCEB) agencies, CISA encourages all organizations to address vulnerabilities listed in the catalog to mitigate cyberattack exposure effectively.

In summary, the text reflects the ongoing efforts within the cybersecurity landscape to identify and address vulnerabilities, making it a critical read for security professionals tasked with protecting infrastructure and ensuring compliance with federal guidelines.