Source URL: https://www.cisa.gov/news-events/alerts/2024/11/14/cisa-adds-two-known-exploited-vulnerabilities-catalog
Source: Alerts
Title: CISA Adds Two Known Exploited Vulnerabilities to Catalog
Feedly Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
CVE-2024-9463 Palo Alto Networks Expedition OS Command Injection Vulnerability
CVE-2024-9465 Palo Alto Networks Expedition SQL Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
AI Summary and Description: Yes
Summary: The text discusses the addition of two new vulnerabilities to CISA’s Known Exploited Vulnerabilities Catalog, emphasizing their significant risk to federal enterprises and urging all organizations to enhance their vulnerability management practices to counter these threats.
Detailed Description: The text highlights recent updates from the Cybersecurity and Infrastructure Security Agency (CISA) regarding two critical vulnerabilities involving Palo Alto Networks’ software. The importance of actively managing these vulnerabilities is underscored by the potential impact on cybersecurity for both federal and private sector organizations.
– **New Vulnerabilities Identified**:
– **CVE-2024-9463**: OS Command Injection Vulnerability
– **CVE-2024-9465**: SQL Injection Vulnerability
– **Security Context**:
– These vulnerabilities are common exploitation tactics used by cyber adversaries, posing significant threats particularly to federal agencies.
– **Regulatory Framework**:
– **Binding Operational Directive (BOD) 22-01**: This directive provides a framework to mitigate risks from known exploited vulnerabilities by mandating remediation efforts within federal civilian agencies.
– Establishes the Known Exploited Vulnerabilities Catalog, requiring rapid response timelines to known vulnerabilities.
– **Broader Recommendations**:
– Although BOD 22-01 targets Federal Civilian Executive Branch (FCEB) agencies, CISA encourages all organizations, regardless of their federal affiliation, to prioritize the remediation of these vulnerabilities to safeguard against cyber threats.
– **Ongoing Commitment**:
– CISA expresses a commitment to continuously update the catalog to reflect new vulnerabilities that meet established criteria for significant risk.
This information is vital for security professionals as it not only details specific vulnerabilities but also emphasizes a proactive approach to vulnerability management, aligning with best practices in cybersecurity.