Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      June 3, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      June 3, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      June 3, 2025

      How To Prevent WordPress SQL Injection Attacks

      June 3, 2025

      SteelSeries reveals new Arctis Nova 3 Wireless headset series for Xbox, PlayStation, Nintendo Switch, and PC

      June 3, 2025

      The Witcher 4 looks absolutely amazing in UE5 technical presentation at State of Unreal 2025

      June 3, 2025

      Razer’s having another go at making it so you never have to charge your wireless gaming mouse, and this time it might have nailed it

      June 3, 2025

      Alienware’s rumored laptop could be the first to feature NVIDIA’s revolutionary Arm-based APU

      June 3, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      easy-live2d – About Make your Live2D as easy to control as a pixi sprite! Live2D Web SDK based on Pixi.js.

      June 3, 2025
      Recent

      easy-live2d – About Make your Live2D as easy to control as a pixi sprite! Live2D Web SDK based on Pixi.js.

      June 3, 2025

      From Kitchen To Conversion

      June 3, 2025

      Perficient Included in Forrester’s AI Technical Services Landscape, Q2 2025

      June 3, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      SteelSeries reveals new Arctis Nova 3 Wireless headset series for Xbox, PlayStation, Nintendo Switch, and PC

      June 3, 2025
      Recent

      SteelSeries reveals new Arctis Nova 3 Wireless headset series for Xbox, PlayStation, Nintendo Switch, and PC

      June 3, 2025

      The Witcher 4 looks absolutely amazing in UE5 technical presentation at State of Unreal 2025

      June 3, 2025

      Razer’s having another go at making it so you never have to charge your wireless gaming mouse, and this time it might have nailed it

      June 3, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»CISA Adds Three Critical Vulnerabilities to KEV Catalog: Immediate Action Urged

    CISA Adds Three Critical Vulnerabilities to KEV Catalog: Immediate Action Urged

    December 7, 2024

    Known Exploited Vulnerabilities

    The Cybersecurity and Infrastructure Security Agency (CISA) recently updated its Known Exploited Vulnerabilities (KEV) Catalog, adding three critical vulnerabilities that are being actively exploited by cybercriminals. The flaws in these products could lead to unauthorized access, data breaches, and service disruptions if left unaddressed. 

    The newly added vulnerabilities include CVE-2023-45727, which affects North Grid Proself and is related to an improper restriction of XML External Entity (XXE) reference. Another critical flaw, CVE-2024-11680, impacts ProjectSend and is caused by an improper authentication vulnerability. Finally, CVE-2024-11667 affects Zyxel firewalls, where a path traversal vulnerability can be exploited. 

    CVE-2023-45727: North Grid Proself XXE Vulnerability 

    The first vulnerability, CVE-2023-45727, affects multiple versions of North Grid’s Proself product suite. These include the Proself Enterprise/Standard Edition (versions 5.62 and earlier), Proself Gateway Edition (versions 1.65 and earlier), and Proself Mail Sanitize Edition (versions 1.08 and earlier). This flaw stems from an improper restriction in the XML External Entity (XXE) processing feature. 

    An attacker can exploit this vulnerability by sending specially crafted XML data to the affected systems. If successful, this could allow remote unauthenticated attackers to access arbitrary files on the server, including those containing sensitive account information. The risk is high as the vulnerability could lead to data manipulation or theft, exposing critical organizational data. 

    The flaw was published on October 18, 2023, and it was added to the KEV catalog shortly after due to its potential impact. Organizations using the affected Proself products are strongly urged to apply patches that address this vulnerability and mitigate the risk of exploitation. 

    CVE-2024-11680: ProjectSend Authentication Bypass 

    The second vulnerability in CISA’s updated KEV catalog is CVE-2024-11680, which affects the ProjectSend file management application. Specifically, versions prior to r1720 are vulnerable to an improper authentication flaw. This vulnerability allows remote attackers to send specially crafted HTTP requests to the options.php file, which enables them to bypass authentication mechanisms. 

    Once authenticated, attackers can make unauthorized changes to the system configuration, including creating new user accounts, uploading malicious content (such as webshells), or embedding harmful JavaScript. With a critical CVSS score of 9.8, this flaw poses online risks for organizations using vulnerable versions of ProjectSend. This vulnerability was published on November 26, 2024, and organizations are advised to immediately update to the latest version to prevent exploitation. 

    CVE-2024-11667: Zyxel Firewalls Path Traversal 

    The third vulnerability, CVE-2024-11667, impacts several Zyxel firewall models, including the ATP series, USG FLEX series, and USG20(W)-VPN series. The vulnerability lies in the web management interface of firmware versions V5.00 through V5.38 for these devices, enabling attackers to perform a path traversal attack. 

    A path traversal vulnerability allows attackers to manipulate file paths in the system, potentially gaining access to sensitive files or uploading malicious files. In the case of these Zyxel firewalls, attackers could exploit this vulnerability to compromise the device’s security.  

    With a CVSS score of 7.5, this flaw is considered high risk but not as critical as the ProjectSend vulnerability. The flaw was published on November 27, 2024, with an update the following day. Organizations using affected Zyxel products should promptly apply security updates to protect against this attack vector. 

    Mitigations for Known Exploited Vulnerabilities 

    The inclusion of CVE-2023-45727, CVE-2024-11680, and CVE-2024-11667 in the CISA Known Exploited Vulnerabilities (KEV) Catalog emphasizes the ongoing cybersecurity challenges faced by industries relying on these vulnerable products. These flaws, which span various attack vectors like XML External Entity (XXE) attacks, improper authentication, and path traversal, pose online risks to organizations using these systems for critical operations.  

    To mitigate these vulnerabilities, organizations must prioritize patch management, strengthen authentication practices, conduct regular security audits, and have incident response plans in place. Proactively addressing these vulnerabilities is essential to protect systems from potential exploits, ensuring the continued security and reliability of operations. 

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticlePhilip Torr: AI to the people | Starmus Highlights
    Next Article ANEL and NOOPDOOR Backdoors Weaponized in New MirrorFace Campaign Against Japan

    Related Posts

    Security

    Alert: Malicious RubyGems Impersonate Fastlane Plugins, Steal CI/CD Data

    June 3, 2025
    Security

    Critical CVSS 9.6: IBM QRadar & Cloud Pak Security Flaws Exposed

    June 3, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    15 Angel Investors in Cybersecurity you should know in 2025

    Web Development

    Hackers Exploiting Cisco CSLU Backdoor—SANS Calls for Urgent Action

    Development

    Autho: Your Authy Desktop Alternative and Beyond (Open Source)

    Development

    TriPeaks – solitaire game

    Linux
    Hostinger

    Highlights

    How to buy a TV during Prime Day and 4th of July like a pro

    July 4, 2024

    Consider these tips to help you navigate these shopping events with savvy and ensure you…

    Why I’m picking up these bargain-priced $7 240W USB-C cables for Cyber Monday

    November 30, 2024

    This clever Kindle trick lets you download 25 books at once – but it’s risky

    February 25, 2025

    Window.js – JavaScript runtime for desktop graphics programming

    June 18, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.