Security News > 2024 > October > Exploited: Cisco, SharePoint, Chrome vulnerabilities

Exploited: Cisco, SharePoint, Chrome vulnerabilities
2024-10-25 10:25

Threat actors have been leveraging zero and n-day vulnerabilities in Cisco security appliances (CVE-2024-20481), Microsoft Sharepoint (CVE-2024-38094), and Google’s Chrome browser (CVE-2024-4947). CVE-2024-20481 (Cisco ASA/FTD) In the past few days, Cisco has released fixes for a slew of vulnerabilities affecting the software powering its security appliances. Among them several are of particular note: CVE-2024-20481, a vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense … More → The post Exploited: Cisco, SharePoint, Chrome vulnerabilities appeared first on Help Net Security.


News URL

https://www.helpnetsecurity.com/2024/10/25/cve-2024-20481-cve-2024-38094-cve-2024-4947/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-10-23 CVE-2024-20481 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Firepower Threat Defense Software
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion.
network
low complexity
cisco CWE-772
5.8
2024-07-09 CVE-2024-38094 Deserialization of Untrusted Data vulnerability in Microsoft Sharepoint Server 2016/2019
Microsoft SharePoint Remote Code Execution Vulnerability
network
low complexity
microsoft CWE-502
7.2
2024-05-15 CVE-2024-4947 Type Confusion vulnerability in multiple products
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
network
low complexity
google fedoraproject CWE-843
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4409 230 3101 1852 602 5785