CISA's list that day
31 March 2022
On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Dasan Gigabit Passive Optical Network (GPON) Routers, Dell dbutil Driver, QNAP Network Attached Storage (NAS) and 3 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2021-21551Insufficient Access Control | Dell dbutil Driver | Patch this weekMetasploit module; EPSS 0.79 | 0.79 | ||
| CVE-2018-10561GPON Routers Authentication Bypass | Dasan Gigabit Passive Optical Network (GPON) Routers | Patch this weekEPSS 0.93 | 0.93 | ||
| CVE-2018-10562GPON Routers Command Injection | Dasan Gigabit Passive Optical Network (GPON) Routers | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| CVE-2021-28799NAS Improper Authorization | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| CVE-2022-1040Authentication Bypass | Sophos Firewall | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2021-34484User Profile Service Privilege Escalation | Microsoft Windows | Patch soon | 0.22 | ||
| CVE-2022-26871Arbitrary File Upload | Trend Micro Apex Central | Patch soon | 0.19 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.