CISA Top 20 Vulnerabilities
Actively exploited CVEs by Chinese State-Sponsored Cyber Actors since 2020
https://www.cisa.gov/uscert/ncas/alerts/aa22-279a
Joint Cybersecurity Advisory (CSA) has released the top Common Vulnerabilities and Exposures (CVEs) used since 2020 by Peoples Republic of China (PRC) state-sponsored cyber actors as assessed by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI). Previously, FortiGuard labs has already published various Outbreaks Alerts included in the released CISA's advisory such as: Apache Log4j, Hikvision Webserver Vulnerability, Atlassian Confluence OGNL RCE Vulnerability, Microsoft Exchange Server RCE Vulnerabilities etc. See the full list at: https://www.fortiguard.com/outbreak-alert Links to dedicated reports on each published outbreak by FortiGuard Labs are added to Additional Resources section below.
Background
The list below shows the FortiGuard IPS signature protections against published CISA top 20 Vulnerabilities: 1. Apache.Log4j.Error.Log.Remote.Code.Execution 2. Pulse.Secure.SSL.VPN.HTML5.Information.Disclosure 3. GitLab.Community.and.Enterprise.Edition.Command.Injection 4. Atlassian.Confluence.OGNL.Remote.Code.Execution 5. MS.Exchange.Server.ProxyRequestHandler.Remote.Code.Exec 6. F5.BIG.IP.Traffic.Management.User.Interface.Directory.Traversal 7. VMware.vCenter.Server.Analytics.Arbitrary.File.Upload 8. Citrix.Application.Delivery.Controller.VPNs.Directory.Traversal 9. Cisco.HyperFlex.HX.Auth.Handling.Command.Injection 10. Arcadyan.Routers.images.Path.Authentication.Bypass 11. Atlassian.Confluence.CVE-2021-26084.Remote.Code.Execution 12. Hikvision.Product.SDK.WebLanguage.Tag.Command.Injection 13. Sitecore.XP.Insecure.Deserialization.Remote.Code.Execution 14. F5.BIG-IP.iControl.REST.Authentication.Bypass 15. APISIX.Admin.API.default.token.Remote.Code.Execution 16. Zoho.ManageEngine.ADSelfService.Plus.Authentication.Bypass 17. MS.Exchange.Server.UM.Core.Remote.Code.Execution 18. MS.Exchange.Server.CVE-2021-26858.Remote.Code.Execution 19. MS.Exchange.Server.CVE-2021-27065.Remote.Code.Execution 20. Apache.HTTP.Server.cgi-bin.Path.Traversal
Announced
October 06, 2022: CISA released the advisory: In the published advisory, NSA, CISA, and FBI has urged U.S. and allied governments, critical infrastructure, and private sector organizations to apply mitigations, increase their defensive posture and reduce the threat of compromise from PRC state-sponsored malicious cyber actors.
Latest Developments
October 18, 2022: FortiGuard Labs Researchers are continually working on protecting organizations and releasing automated signature updates throughout the Security Fabric such as: Next-Gen Intrusion preventions systems (IPS): FortiClient Endpoint Security Fabric Agent: FortiWEB Web Application Firewall (WAF):
arrow_icon
PROTECT

Countermeasures across the security fabric for protecting assets, data and network from cybersecurity events:

Reconnaissance
Weaponization

Delivery

Vulnerability

Detects and Blocks attack attempts related to CISA Top 20 Vulnerabilities

DB 1.348

Exploitation

IPS

Detects and Blocks attack attempts related to CISA Top 20 Vulnerabilities

DB 22.414
DB 22.414
DB 22.414
DB 22.414
DB 22.414
Web App Security

Detects and Blocks attack attempts related to CISA Top 20 Vulnerabilities

DB 0.00330
DB 1.00038
Installation
C2
Action
arrow_icon
DETECT

Find and correlate important information to identify an outbreak, the following updates are available to raise alert and generate reports:

Outbreak Detection

DB 1.003
DB 1.00067
IOC

DB 0.02355
DB 0.02355
DB 0.02355
Threat Hunting
Content Update

DB 308
arrow_icon
RESPOND

Develop containment techniques to mitigate impacts of security events:

Automated Response

Services that can automaticlly respond to this outbreak.

Assisted Response Services

Experts to assist you with analysis, containment and response activities.

arrow_icon
RECOVER

Improve security posture and processes by implementing security awareness and training, in preparation for (and recovery from) security incidents:

InfoSec Services

Security readiness and awareness training for SOC teams, InfoSec and general employees.

arrow_icon
IDENTIFY

Identify processes and assets that need protection:

Attack Surface Monitoring (Inside & Outside)

Security reconnaissance and penetration testing services, covering both internal & external attack vectors, including those introduced internally via software supply chain.

Additional Resources

Learn more about FortiGuard Outbreak Alerts