Posting Date: 2025/06/19

【Vulnerability Alert】CISA Adds 4 Known Exploited Vulnerabilities to KEV Catalog (2025/06/09-2025/06/15)

  • Subject: 【Vulnerability Alert】CISA Adds 4 Known Exploited Vulnerabilities to KEV Catalog (2025/06/09-2025/06/15)
  • Content:
    • Forwarded from TWCERTCC-200-202506-00000011
    1. 【CVE-2024-42009】RoundCube Webmail Cross-Site Scripting Vulnerability (CVSS v3.1: 9.3)
    2. 【CVE-2025-32433】Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 10.0)
      • 【Exploited by Ransomware: Unknown】Erlang/OTP SSH server has a missing authentication for critical function vulnerability. This vulnerability may allow an attacker to execute arbitrary commands without providing valid credentials, leading to unauthenticated remote code execution. Malicious users can exploit vulnerabilities in the SSH protocol message handling to gain unauthorized access to affected systems. This vulnerability may affect multiple products using Erlang/OTP SSH server, including but not limited to Cisco, NetApp and SUSE.
      • 【Affected Platforms】Please refer to the official list of affected versions.
    3. 【CVE-2025-33053】Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability (CVSS v3.1: 8.8)
    4. 【CVE-2025-24016】Wazuh Server Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.9)
  • Affected Platforms:
    • Detailed content in the “Affected Platforms” section of the content description.

Computer and Communications Center
Network Systems Division