CISA | Alerts
Follow
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities affect D-Link devices, specifically the DCS-2530L, DCS-2670L, and DNR-322L models. The newly listed vulnerabilities include an unspecified vulnerability, a command injection vulnerability, and a code download without integrity check vulnerability. These types of vulnerabilities are frequently exploited by cyber attackers, posing significant risks. Binding Operational Directive (BOD) 22-01 established the KEV Catalog to identify vulnerabilities with significant risk to the federal enterprise. This directive mandates that Federal Civilian Executive Branch (FCEB) agencies remediate these vulnerabilities by their due dates. The goal is to protect FCEB networks from active cyber threats. While BOD 22-01 applies only to FCEB agencies, CISA strongly recommends all organizations prioritize remediating KEV Catalog vulnerabilities. This proactive approach is crucial for reducing exposure to cyberattacks. CISA will continue to update the KEV Catalog with vulnerabilities that meet its established criteria.