CISA's list that day
24 October 2022
On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in GIGABYTE Multiple Products and Cisco AnyConnect Secure. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2020-3153Mobility Client for Windows Uncontrolled Search Path | Cisco AnyConnect Secure | Patch this weekRansomware use; Metasploit module | 0.28 | ||
| CVE-2020-3433Mobility Client for Windows DLL Hijacking | Cisco AnyConnect Secure | Patch this weekRansomware use; Metasploit module | 0.10 | ||
| CVE-2018-19323Privilege Escalation | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.08 | ||
| CVE-2018-19320Unspecified | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.04 | ||
| CVE-2018-19321Privilege Escalation | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.04 | ||
| CVE-2018-19322Code Execution | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.02 |
Our record of CISA's changes begins on 24 January 2025. For earlier days this page lists the entries CISA dates to this day; changes CISA made that day are not known to us.