Skip to content
feed: live
0dayNews
cisa kev
● Breaking

CISA: Five Flax Typhoon CVEs Added, Feds Have Until Oct 11

CISA added five vulnerabilities tied to China's Flax Typhoon to its KEV catalog on Oct 8; federal agencies must patch or discontinue use by October 11.

CISA: Five Flax Typhoon CVEs Added, Feds Have Until Oct 11
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on October 8, citing active exploitation by Flax Typhoon, a Chinese state-sponsored group linked to Beijing contractor Integrity Technology Group. Federal civilian executive branch agencies have until October 11 to patch or discontinue affected products under BOD 26-04.

All five carry the same remediation deadline. Here is what is on the list:

CVE Product CVSS Vulnerability Class
CVE-2015-3306 ProFTPD 10.0 Improper access control
CVE-2021-3199 ONLYOFFICE Docs 9.8 Path traversal / RCE chain
CVE-2016-3081 Apache Struts 8.1 Command injection via DMI
CVE-2015-5477 ISC BIND 7.8 DoS via TKEY queries
CVE-2023-22894 Strapi 4.9 Cleartext credential exposure

These are not new vulnerabilities. The oldest dates to 2015. What is new is confirmed, active exploitation at scale by a Chinese APT that the FBI disrupted earlier this week. The additions follow a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the UK, and the U.S. documenting Flax Typhoon’s use of scanning tools, cross-site scripting attacks, and password spraying against Microsoft Exchange servers, with persistence maintained through VPN software.

What to actually patch first

Start with CVE-2015-3306. ProFTPD’s CVSS 10.0 improper access control flaw lets remote attackers read and write arbitrary files via the SITE CPFR and SITE CPTO commands. A patch has been available since 2015. Upgrade to ProFTPD 1.3.5 or later.

ONLYOFFICE Docs users should check CVE-2021-3199: the path traversal in image upload parameters can chain into remote code execution when JWT is in use. Check your ONLYOFFICE version against the vendor’s fix.

For Apache Struts, CVE-2016-3081 requires Dynamic Method Invocation to be enabled to trigger command injection via the method: prefix. Disable DMI if you have not already and upgrade past the vulnerable range.

CVE-2015-5477 in ISC BIND crashes named via crafted TKEY queries. BIND 9.10.2-P3 or later resolves it. If you are still running unpatched BIND on a public-facing resolver, this is a straightforward denial-of-service exposure.

Strapi’s CVE-2023-22894 is the lowest CVSS of the batch at 4.9, but it exposes sensitive user details through the admin panel’s query filter. CISA notes it may affect end-of-life versions and can chain with CVE-2023-22621 for RCE. Strapi’s advisory recommends upgrading to a supported version.

Non-federal context

The October 11 deadline is legally binding only for FCEB agencies. That said, these flaws are being actively weaponized by a nation-state actor with a documented interest in critical infrastructure. If you operate ProFTPD, ONLYOFFICE, an Apache Struts app, BIND, or a Strapi instance, the federal deadline is a useful forcing function regardless of your sector.

Sources: CISA KEV catalog, The Hacker News reporting on the KEV additions, CISA BOD 26-04.

Related: CISA Adds Seven Flaws Tied to Reverse Shells and Miners, CISA KEV: Cisco, Citrix, Fortinet in September Batch, What Is the CISA KEV Catalog.

Related CVEs
  • [ CRITICAL ]CVE-2015-3306ProFTPD Improper Access Control Vulnerability
  • [ CRITICAL ]CVE-2021-3199ONLYOFFICE Docs Server Path Traversal Vulnerability
  • [ HIGH ]CVE-2016-3081Apache Struts Command Injection Vulnerability
  • [ HIGH ]CVE-2015-5477 ISC BIND Data Processing Errors Vulnerability
  • [ MEDIUM ]CVE-2023-22894Strapi Cleartext Storage of Sensitive Information Vulnerability

Found this useful? Share it.