Kwetsbaarheden - Week 33

Het CSIRT-DSP maakt op wekelijkse basis een selectie van kwetsbaarheden, waarbij het CSIRT-DSP de inschatting heeft gemaakt dat deze relevant zijn voor digitale dienstverleners.

Het betreft een selectie van 'Medium' en 'High' kwetsbaarheden. Voor de inschatting hiervan wordt er gebruik gemaakt van de CVSS 3.1 base scores indien deze beschikbaar zijn. Indien deze niet beschikbaar zijn, zal dit worden aangegeven met 'n/a'.

Critical & High

OPNsense
https://nvd.nist.gov/vuln/detail/CVE-2023-38997 (9.8)
https://nvd.nist.gov/vuln/detail/CVE-2023-39001 (9.8)
https://nvd.nist.gov/vuln/detail/CVE-2023-39008 (9.8)
https://nvd.nist.gov/vuln/detail/CVE-2023-39007 (9.6)
https://nvd.nist.gov/vuln/detail/CVE-2023-39004 (9.8)
https://nvd.nist.gov/vuln/detail/CVE-2023-39003 (7.5)
https://nvd.nist.gov/vuln/detail/CVE-2023-39005 (7.5)
https://nvd.nist.gov/vuln/detail/CVE-2023-38999 (6.5)
https://nvd.nist.gov/vuln/detail/CVE-2023-38998 (6.1)
https://nvd.nist.gov/vuln/detail/CVE-2023-39000 (6.1)
https://nvd.nist.gov/vuln/detail/CVE-2023-39002 (6.1)
https://nvd.nist.gov/vuln/detail/CVE-2023-39006 (5.4)

Apache Traffic Server
https://nvd.nist.gov/vuln/detail/cve-2023-33934 (9.1)
https://nvd.nist.gov/vuln/detail/cve-2022-47185 (7.5)

OpenNMS Meridian / Horizon
https://nvd.nist.gov/vuln/detail/CVE-2023-0871 (8.8)
https://nvd.nist.gov/vuln/detail/CVE-2023-0872 (8.2)

Paessler PRTG Network Monitor
https://kb.paessler.com/en/topic/91845-multiple-vulnerabilites-fixed-in… (8.8-4.7)

Tribe29 Checkmk
https://nvd.nist.gov/vuln/detail/CVE-2023-31209 (8.8)

Nextcloud Server / Enterprise Server
https://nvd.nist.gov/vuln/detail/CVE-2023-39963 (8.1)
https://nvd.nist.gov/vuln/detail/CVE-2023-39962 (7.7)
https://nvd.nist.gov/vuln/detail/CVE-2023-39952 (6.5)
https://nvd.nist.gov/vuln/detail/CVE-2023-39958 (5.8)

Dell PowerScale OneFS
https://www.dell.com/support/kbdoc/nl-nl/000216717/dsa-2023-269-securit… (7.8-5.3)

Dell Storage Integration Tools for VMware (DSITV)
https://www.dell.com/support/kbdoc/nl-nl/000216615/dsa-2023-282-securit… (7.8)

HPE Aruba Networking Virtual Intranet Access (VIA)
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-011.txt (7.8-7.1)

Adobe Commerce / Magento
https://nvd.nist.gov/vuln/detail/CVE-2023-38207 (7.5)
https://nvd.nist.gov/vuln/detail/CVE-2023-38208 (7.2)
https://nvd.nist.gov/vuln/detail/CVE-2023-38209 (6.5)

HashiCorp Consul and Consul Enterprise
https://nvd.nist.gov/vuln/detail/CVE-2023-3518 (7.4)

Nextcloud Talk Android
https://nvd.nist.gov/vuln/detail/CVE-2023-39957 (7.2)

Zoho ManageEngine Applications Manager
https://nvd.nist.gov/vuln/detail/CVE-2023-38333 (high)

Cacti
https://nvd.nist.gov/vuln/detail/CVE-2023-37543 (n/a)

Ivanti Avalanche
https://forums.ivanti.com/s/article/Avalanche-Vulnerabilities-Addressed… (n/a)

Medium

SolarWinds Serv-U
https://nvd.nist.gov/vuln/detail/CVE-2023-35179 (6.6)

Zyxel XGS2220 / XMG1930 / XS1930 series switches
https://nvd.nist.gov/vuln/detail/CVE-2023-28768 (6.5)

HCL DRYiCE MyCloud
https://nvd.nist.gov/vuln/detail/CVE-2023-23346 (6.4)
https://nvd.nist.gov/vuln/detail/CVE-2023-23347 (6.4)

Nextcloud OpenID Connect (OIDC)
https://nvd.nist.gov/vuln/detail/CVE-2023-39953 (4.8)

HAProxy
https://nvd.nist.gov/vuln/detail/CVE-2023-40225 (n/a)

LibreNMS
https://nvd.nist.gov/vuln/detail/CVE-2023-4347 (n/a)

Netbox
https://nvd.nist.gov/vuln/detail/CVE-2023-37625 (n/a)