Start with Identity
Protocol · 27 briefs · 17 on CISA KEV

Appliance, CI, and control-plane auth CVEs

RMM, VPN, CI, print, and mail admin planes keep failing authentication. They are identity products whether the IAM team owns them or not.

How this protocol fails

ScreenConnect, TeamCity, PaperCut, N-able N-central, Ivanti EPMM/Sentry/Connect Secure, Citrix Bleed, Outlook NTLM, Zimbra MFA backup codes, SmarterMail, Check Point hash leaks, BeyondTrust PRA. The pattern is an internet-facing management login, an alternate path, and ransomware or a state actor three days later. CISA KEV is concentrated here. Incomplete first fixes (N-central, FortiCloud SSO, TeamCity sequels) are how the same incident lasts a year.

What security people should do

  • Patch KEV items on internet-facing admin planes first. Confirm the build string, not the calendar date of the last change window.
  • If the box was reachable at disclosure, rebuild and rotate. A hotfix on a planted admin is not eviction.
  • Take management UIs off the internet. Put them behind phishing-resistant MFA and a jump path.
  • Hunt for rogue admins, unexpected tunnels, and sessions with no matching interactive login.

CVEs in this category

27
Other
17
On CISA KEV
17
Actively exploited
27
Showing
Severity
Year
Status

Showing 27 of 27

Working this protocol in production and see a brief we should add or correct? Email [email protected] or volunteer as a CVE Analyst.