So, we have summarized the vulnerabilities that need to be addressed as we continued last month.
For those involved in SOC/security operations, we will identify the most recent vulnerabilities to watchCybersecurity
and the Known Exploited Vulnerbilities Catalog published by the Infrastructure Security Agency (CISA) and the Common Vulnerabilities and Exposures (CVEs) published by The MITRE Corporation Based on Records, we have written explanations + how to deal with it. Please take advantage of this to reduce the operational burden while visualizing and prioritizing risks.
What is Known Exploited Vulnerabilities Catalog?
The Known Exploited Vulnerabilities (KEV) Catalog is a list of "Vulnerabilities Confirmed to Have Actually Exploited" published by CISA. Therefore, it can be used as a criterion for quickly responding to vulnerabilities that are actually used in cyberattacks.
What is Common Vulnerabilities and Exposures?
Common Vulnerabilities and Exposures (CVEs) are identifiers assigned to vulnerabilities in individual products published by The MITRE Corporation. An organization of security professionals, such as security vendors, product development vendors, and researchers, evaluates reported vulnerabilities and assigns identifiers.
Overview of each vulnerability and how to address it
CVE-2025-64155
Product/Scope of Influence
- FortiSIEM 7.4: 7.4.0
- FortiSIEM 7.3: 7.3.0 ~ 7.3.4
- FortiSIEM 7.2: 7.2.0 ~ 7.2.6
- FortiSIEM 7.1: 7.1.0 ~ 7.1.8
- FortiSIEM 7.0: 7.0.0 ~ 7.0.4
- FortiSIEM 6.7: 6.7.0 ~ 6.7.10
CVSS Score 9.8
Overview/Key Takeaways FortiSIEM is a Security Information and Event Management (SIEM) product provided by Fortinet. This vulnerability allows an unauthenticated attacker to send a crafted TCP request due to improper handling of special characters used in OS commands (CWE-78. The vulnerability does not affect Collector nodes, only Super and Worker nodes.
Points to Deal with
A temporary workaround is to close the port (7900) for phMonitor. However, permanently, upgrade each product.
- FortiSIEM 7.4: 7.4.1 ~
- FortiSIEM 7.3: 7.3.5 ~
- FortiSIEM 7.2: 7.2.7 ~
- FortiSIEM 7.1: 7.1.9 ~
- FortiSIEM 7.0: Migrating to the latest product version
- FortiSIEM 6.7: Migrating to the latest product version
References
CVE-2025-20393
Product/Scope of Influence
- Cisco Secure Email
- 14.0.0-698
- 13.5.1-277
- 13.0.0-392
- 14.2.0-620
- 13.0.5-007
- 13.5.4-038
- 14.2.1-020
- 14.3.0-032
- 15.0.0-104
- 15.0.1-030
- 15.5.0-048
- 15.5.1-055
- 15.5.2-018
- 16.0.0-050
- 15.0.3-002
- 16.0.0-054
- 15.5.3-022
- 16.0.1-017
- Cisco Secure Email and Web Manager
- 13.6.2-023
- 13.6.2-078
- 13.0.0-249
- 13.0.0-277
- 13.8.1-052
- 13.8.1-068
- 13.8.1-074
- 14.0.0-404
- 12.8.1-002
- 14.1.0-227
- 13.6.1-201
- 14.2.0-203
- 14.2.0-212
- 12.8.1-021
- 13.8.1-108
- 14.2.0-224
- 14.3.0-120
- 15.0.0-334
- 15.5.1-024
- 15.5.1-029
- 15.5.2-005
- 16.0.0-195
- 15.5.3-017
- 16.0.1-010
- 15.0.1-035
- 16.0.2-088
CVSS Score 10.0
Overview/Key Points
Cisco Secure Email is Cisco's suite of email security products designed to protect corporate email communications. Its main purpose is to detect and block spam, phishing, and malware-containing emails, and is placed at the front of the email infrastructure in many companies. The vulnerability exploited this time allows an attacker to execute arbitrary commands with root privileges. (CWE-20)
Points to Deal with
Security patches have already been distributed, so update to the latest version. It has been released as updating by following the steps below. Please refer to the official documentation for details.
- Select System Administration > System Upgrade.
- Click Upgrade Options.
- Click Download and Install.
- Select the release you want to upgrade to.
- In the Upgrade Preparation section, select the appropriate option as needed.
- Click Proceed to start the upgrade. The progress is displayed in the progress bar.
References
- Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
CVE-2025-31201
Product/Scope of Influence
- visionOS: ~2.4
- iOS/iPadOS: ~18.4
- tvOS: ~18.4
- macOS: ~15.4
CVSS Score 9.8
Overview/Key Points
A vulnerability has been reported in the operating system of all Apple products that could bypass the processing of pointer authentication codes (PACs). Pointer authentication codes (PACs) are used to prevent memory destruction. The system software and built-in apps use PACs to prevent tampering with function pointers and return addresses (code pointers). (Pointer Authentication Code - Apple Platform Security)
Points to Deal with
Security patches have already been distributed by Apple. Update each product to the latest version.
- visionOS: 2.4.1
- iOS/iPadOS: 18.4.1
- tvOS: 18.4.1
- macOS: 15.4.1
References
What Colorkrew can help Colorkrew can help ColorkrewSecurity provides SOC services that support attack detection and CSIRT response to vulnerabilities such as the above.
If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.