From 468ea2b3285346be321c0d0c2b958cfea68aec20 Mon Sep 17 00:00:00 2001 From: AboutCode Automation Date: Thu, 23 Jan 2025 00:11:07 +0000 Subject: [PATCH] Update KEV: Thu Jan 23 00:11:07 UTC 2025 Signed-off-by: AboutCode Automation --- known_exploited_vulnerabilities.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/known_exploited_vulnerabilities.json b/known_exploited_vulnerabilities.json index d0735d4..9e5667f 100644 --- a/known_exploited_vulnerabilities.json +++ b/known_exploited_vulnerabilities.json @@ -1,7 +1,7 @@ { "title": "CISA Catalog of Known Exploited Vulnerabilities", - "catalogVersion": "2025.01.16", - "dateReleased": "2025-01-16T15:00:56.7822Z", + "catalogVersion": "2025.01.22", + "dateReleased": "2025-01-22T19:49:22.4091Z", "count": 1250, "vulnerabilities": [ { @@ -67,10 +67,10 @@ { "cveID": "CVE-2024-55591", "vendorProject": "Fortinet", - "product": "FortiOS", - "vulnerabilityName": "Fortinet FortiOS Authorization Bypass Vulnerability", + "product": "FortiOS and FortiProxy", + "vulnerabilityName": "Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability", "dateAdded": "2025-01-14", - "shortDescription": "Fortinet FortiOS contains an authorization bypass vulnerability that may allow an unauthenticated remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.", + "shortDescription": "Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.", "requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.", "dueDate": "2025-01-21", "knownRansomwareCampaignUse": "Unknown",