CISA เพิ่มช่องโหว่ Cisco ISE, PaperCut ลงในแคตตาล็อก KEV

กรกฎาคม 28, 2025 • César Daniel Barreto

CISA Adds Three Known Exploited Vulnerabilities to Catalog cybersecurity vulnerability alert CVSS

On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services Engine (ISE) and one in PaperCut print-management software. Under Binding Operational Directive 22-01, federal civilian agencies were given until August 18, 2025 to remediate them.

The Cisco ISE vulnerabilities: unauthenticated root RCE

The two Cisco flaws are as severe as they come. CVE-2025-20281 และ CVE-2025-20337 both carry the maximum CVSS score of 10.0, and both let an unauthenticated, remote attacker execute arbitrary code with root privileges on Cisco ISE and the ISE Passive Identity Connector (ISE-PIC). One stems from insufficient input validation in an API endpoint; the other from unsafe deserialization. Only releases 3.3 and 3.4 are affected — but Cisco warns that earlier hot-fixes do not fully close the hole, so administrators must upgrade to ISE 3.3 Patch 7 หรือ 3.4 Patch 2. Cisco’s PSIRT confirmed attempted exploitation in the wild in late July, and a public proof-of-concept has since circulated.

The PaperCut NG/MF flaw

The third entry, CVE-2023-2533, is a cross-site request forgery (CSRF) vulnerability in PaperCut NG/MF rated CVSS 8.4. By luring an authenticated administrator with an active session into clicking a malicious link, an attacker can alter security settings and, under the right conditions, achieve remote code execution. Versions 21.2.0 through 22.0.12 are affected; the fix landed in 22.1.1 and later.

What to do now

If you run Cisco ISE 3.3 or 3.4, patch to the fixed builds immediately — unauthenticated, root-level remote code execution is a worst-case scenario, and exploit code is already public. PaperCut administrators should update to 22.1.1 or later and treat any unexpected configuration changes as a potential compromise. Because all three vulnerabilities now sit in CISA’s KEV catalog, active exploitation is ongoing, not theoretical — these are fixes to prioritize this week, not next quarter.

ซีซาร์ ดาเนียล บาร์เรโต, ผู้เขียนด้านความปลอดภัยทางไซเบอร์ที่ Security Briefing

เซซาร์ ดาเนียล บาร์เรโต

César Daniel Barreto เป็นนักเขียนและผู้เชี่ยวชาญด้านความปลอดภัยทางไซเบอร์ที่มีชื่อเสียง ซึ่งเป็นที่รู้จักจากความรู้เชิงลึกและความสามารถในการทำให้หัวข้อความปลอดภัยทางไซเบอร์ที่ซับซ้อนนั้นง่ายขึ้น ด้วยประสบการณ์อันยาวนานด้านความปลอดภัยเครือข่ายและการปกป้องข้อมูล เขามักจะเขียนบทความเชิงลึกและการวิเคราะห์เกี่ยวกับแนวโน้มด้านความปลอดภัยทางไซเบอร์ล่าสุดเพื่อให้ความรู้แก่ทั้งผู้เชี่ยวชาญและสาธารณชน

  1. ภัยคุกคามไซเบอร์ที่ซ่อนอยู่ที่แพลตฟอร์ม iGaming กำลังเผชิญ
  2. คู่มือฉบับสมบูรณ์สำหรับการทดสอบการเจาะระบบเครือข่าย
  3. มัลแวร์ 101: มัลแวร์คืออะไร วิธีป้องกันการโจมตี และวิธีลบมัลแวร์ออกจากคอมพิวเตอร์ของคุณ
  4. พบแอพ Android ที่มีมัลแวร์บน Play Store
  5. Cryptojacking: เคล็ดลับการตรวจจับและการป้องกัน
  6. ความสำคัญของการรักษาความปลอดภัยทางไซเบอร์ในแพลตฟอร์มเกมออนไลน์
  7. 8 วิธีที่บล็อกเชนกำลังปรับปรุงความปลอดภัยสำหรับนักเล่นเกม
  8. วิธีลบมัลแวร์ออกจาก Google Chrome
  9. Temu ปลอดภัยสำหรับการใช้บัตรเครดิตหรือไม่?
  10. การลงทุนระยะสั้นหรือระยะยาว? สกุลเงินดิจิทัลชั้นนำสำหรับทั้งสองทางเลือกนี้
  11. อะไรทำให้การชำระเงินด้วยสกุลเงินดิจิทัลปลอดภัยมาก 
  12. ความเป็นส่วนตัวและความปลอดภัยเป็นลักษณะสำคัญของ Blockchain: ตอนที่ 3

Login

Already have an account? Sign in to pick up where you left off.

Register

New here? Create an account to follow our latest security briefings.

thThai