Lucene search

K
icsIndustrial Control Systems Cyber Emergency Response TeamAA23-339A
HistoryDec 05, 2023 - 12:00 p.m.

Threat Actors Exploit Adobe ColdFusion CVE-2023-26360 for Initial Access to Government Servers

2023-12-0512:00:00
Industrial Control Systems Cyber Emergency Response Team
www.cisa.gov
41
threat actors
exploit
adobe coldfusion
cve-2023-26360
government servers
vulnerabilities
network segmentation
multifactor authentication
webmail
vpn
critical systems

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

8.9

Confidence

High

EPSS

0.965

Percentile

99.6%

Actions to take today to mitigate malicious cyber activity:

  1. Prioritize remediating known exploited vulnerabilities.
  2. Employ proper network segmentation.
  3. Enable multifactor authentication (MFA) for all services to the extent possible, particularly for webmail, VPN, and accounts that access critical systems.

References

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

8.9

Confidence

High

EPSS

0.965

Percentile

99.6%