Heimdal Security Blog

CISA Warning! 8 Actively Exploited Flaws in Samsung and D-Link Devices

flaws affecting Samsung

The US Cybersecurity and Infrastructure Security Agency (CISA) added 6 flaws affecting Samsung smartphones to its Known Exploited Vulnerabilities Catalog. On the same day, CISA also added 2 other vulnerabilities impacting D-Link devices.

Although security specialists released patches for all 8 CVEs back in 2021, researchers currently found evidence of active exploitation.

More about the Samsung and D-Link Vulnerabilities

CISA issued an alert regarding the 8 actively exploited vulnerabilities on June 29th, 2023. You can find them listed below, with details.

Samsung flaws:

D-Link flaws:

Both D-Link router and access point vulnerabilities were previously exploited by a Mirai botnet variant. Their CVSS scores go from critical to high.

Future Risks and Mitigation Measures

While the D-Link flaws were exploited by a Mirai botnet variant, it is yet unknown how were the Samsung vulnerabilities exploited in the wild. According to researchers

given the nature of the targeting, it’s likely that they may have been put to use by a commercial spyware vendor in highly targeted attacks.

Source

Threat actors often use vulnerabilities like those of Samsung and D-link as attack vectors to compromise networks.

Consequently, CISA notified all Federal Civilian Executive Branch (FCEB) agencies to apply available patches by July 20, 2023. In addition, CISA urged all organizations to prioritize patching of flaws in the Known Exploited Vulnerabilities Catalog. Automated patch management and proper vulnerability management measures increase the chances to safeguard a company`s network and assets.

If you liked this article, follow us on LinkedIn, Twitter, Facebook, and Youtube, for more cybersecurity news and topics.

Install and Patch Software. Close Vulnerabilities. Achieve Compliance.

Heimdal® Patch & Asset Management

Remotely and automatically install Windows, Linux and 3rd party patches and manage your software inventory.
  • Create policies that meet your exact needs;
  • Full compliance and CVE/CVSS audit trail;
  • Gain extensive vulnerability intelligence;
  • And much more than we can fit in here...
Try it for FREE today 30-day Free Trial. Offer valid only for companies.