{"id":813270,"date":"2023-07-03T16:52:34","date_gmt":"2023-07-03T18:52:34","guid":{"rendered":"https:\/\/teknomers.com\/fr\/la-cisa-signale-8-failles-activement-exploitees-dans-les-appareils-samsung-et-d-link\/"},"modified":"2023-07-03T16:52:38","modified_gmt":"2023-07-03T18:52:38","slug":"la-cisa-signale-8-failles-activement-exploitees-dans-les-appareils-samsung-et-d-link","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/la-cisa-signale-8-failles-activement-exploitees-dans-les-appareils-samsung-et-d-link\/","title":{"rendered":"La CISA signale 8 failles activement exploit\u00e9es dans les appareils Samsung et D-Link"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">03 juil. 2023<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><\/span><span class=\"p-tags\">S\u00e9curit\u00e9 mobile \/ S\u00e9curit\u00e9 r\u00e9seau<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><\/div>\n<p>La Cybersecurity and Infrastructure Security Agency (CISA) des \u00c9tats-Unis a <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/06\/29\/cisa-adds-eight-known-exploited-vulnerabilities-catalog\" target=\"_blank\">mis<\/a> un ensemble de huit failles aux Vuln\u00e9rabilit\u00e9s Exploit\u00e9es Connues (<a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>), sur la base de preuves d&#8217;exploitation active.<\/p>\n<p>Cela comprend six lacunes affectant les smartphones Samsung et deux vuln\u00e9rabilit\u00e9s affectant les appareils D-Link.  Toutes les failles ont \u00e9t\u00e9 corrig\u00e9es \u00e0 partir de 2021.<\/p>\n<ul>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-25394\" target=\"_blank\"><strong>CVE-2021-25394<\/strong><\/a>  (Score CVSS\u00a0: 6,4) &#8211; Vuln\u00e9rabilit\u00e9 des conditions de concurrence des appareils mobiles Samsung<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-25395\" target=\"_blank\"><strong>CVE-2021-25395<\/strong><\/a>  (Score CVSS\u00a0: 6,4) &#8211; Vuln\u00e9rabilit\u00e9 des conditions de concurrence des appareils mobiles Samsung<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-25371\" target=\"_blank\"><strong>CVE-2021-25371<\/strong><\/a>  (Score CVSS\u00a0: 6,7) &#8211; Une vuln\u00e9rabilit\u00e9 non sp\u00e9cifi\u00e9e dans le pilote DSP utilis\u00e9 dans les appareils mobiles Samsung qui permet le chargement de biblioth\u00e8ques ELF arbitraires<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-25372\" target=\"_blank\"><strong>CVE-2021-25372<\/strong><\/a>  (Score CVSS\u00a0: 6,7) &#8211; V\u00e9rification incorrecte des limites des appareils mobiles Samsung dans le pilote DSP des appareils mobiles Samsung<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-25487\" target=\"_blank\"><strong>CVE-2021-25487<\/strong><\/a>  (Score CVSS\u00a0: 7,8) &#8211; Vuln\u00e9rabilit\u00e9 de lecture hors limites des appareils mobiles Samsung entra\u00eenant l&#8217;ex\u00e9cution de code arbitraire<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-25489\" target=\"_blank\"><strong>CVE-2021-25489<\/strong><\/a>  (Score CVSS\u00a0: 5,5) &#8211; Vuln\u00e9rabilit\u00e9 de validation d&#8217;entr\u00e9e incorrecte des appareils mobiles Samsung entra\u00eenant une panique du noyau<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-17621\" target=\"_blank\"><strong>CVE-2019-17621<\/strong><\/a>  (Score CVSS\u00a0: 9,8) &#8211; Une vuln\u00e9rabilit\u00e9 d&#8217;ex\u00e9cution de code \u00e0 distance non authentifi\u00e9e dans le routeur D-Link DIR-859<\/li>\n<li><a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-20500\" target=\"_blank\"><strong>CVE-2019-20500<\/strong><\/a>  (Score CVSS\u00a0: 7,8) &#8211; Une vuln\u00e9rabilit\u00e9 d&#8217;injection de commande de syst\u00e8me d&#8217;exploitation authentifi\u00e9e dans D-Link DWL-2600AP<\/li>\n<\/ul>\n<p>L&#8217;ajout des deux vuln\u00e9rabilit\u00e9s D-Link fait suite \u00e0 un rapport de l&#8217;unit\u00e9 42 de Palo Alto Networks le mois dernier sur les acteurs de la menace associ\u00e9s \u00e0 une variante du botnet Mirai <a rel=\"nofollow noopener\" href=\"https:\/\/unit42.paloaltonetworks.com\/mirai-variant-targets-iot-exploits\/\" target=\"_blank\">tirer parti<\/a> failles dans plusieurs appareils IoT pour propager le malware dans une s\u00e9rie d&#8217;attaques \u00e0 partir de mars 2023.<\/p>\n<p>Cependant, on ne sait pas imm\u00e9diatement comment les failles des appareils Samsung sont exploit\u00e9es dans la nature.  Mais \u00e9tant donn\u00e9 la nature du ciblage, il est probable qu&#8217;ils aient \u00e9t\u00e9 utilis\u00e9s par un fournisseur de logiciels espions commerciaux dans des attaques tr\u00e8s cibl\u00e9es.<\/p>\n<p>Il convient de noter que Google Project Zero a r\u00e9v\u00e9l\u00e9 un ensemble de failles en novembre 2022 qui, selon lui, \u00e9taient <a rel=\"nofollow noopener\" href=\"https:\/\/googleprojectzero.blogspot.com\/2022\/11\/a-very-powerful-clipboard-samsung-in-the-wild-exploit-chain.html\" target=\"_blank\">arm\u00e9<\/a> dans le cadre d&#8217;une cha\u00eene d&#8217;exploitation visant les combin\u00e9s Samsung.<\/p>\n<p>\u00c0 la lumi\u00e8re de l&#8217;exploitation active, les agences du pouvoir ex\u00e9cutif civil f\u00e9d\u00e9ral (FCEB) sont tenues d&#8217;appliquer les correctifs n\u00e9cessaires d&#8217;ici le 20 juillet 2023 pour s\u00e9curiser leurs r\u00e9seaux contre les menaces potentielles.<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant ?  Suivez-nous sur <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Twitter <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">LinkedIn<\/a> pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2023\/07\/cisa-flags-8-actively-exploited-flaws.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80203 juil. 2023\ue804Ravie LakshmananS\u00e9curit\u00e9 mobile \/ S\u00e9curit\u00e9 r\u00e9seau La Cybersecurity and Infrastructure Security Agency (CISA) des \u00c9tats-Unis a mis un ensemble de huit failles aux Vuln\u00e9rabilit\u00e9s Exploit\u00e9es Connues (KEV), sur la base de preuves d&#8217;exploitation active. Cela comprend six lacunes affectant les smartphones Samsung et deux vuln\u00e9rabilit\u00e9s affectant les appareils D-Link. Toutes les failles ont [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":813271,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4807,8737,4805,4168,4158,4165,4161,429,106877,4808,4806,4157,4159,4171,4170,65,4167,4160,4163,4162,7850,4172,4169,5520,4166,4164],"class_list":["post-813270","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-activement","tag-appareils","tag-cisa","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-dlink","tag-exploitees","tag-failles","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-samsung","tag-securite-informatique","tag-securite-internet","tag-signale","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/813270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=813270"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/813270\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/813271"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=813270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=813270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=813270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}