CyberzSOC

Publication detail
← Back to advisories & guidance

CISA Releases Analysis of FY23 Risk and Vulnerability Assessments ↗ source

September 13, 2024 CISA Alert

Summary

Concurrently, the United States Coast Guard (USCG) conducts RVAs on maritime CI operated by SLTT and The RVA is intended to assess the entity’s network capabilities and network defenses against known threats. In Fiscal Year 2023 (FY23), CISA and the USCG conducted a combined total of 143 RVAs across multiple CI sectors.1 Each RVA maps the results to the MITRE ATT&CK® framework, which includes 14 tactics, techniques, and procedures (TTPs) that cyber threat actors use to obtain and maintain unauthorized access to a network or system. The goal of the RVA analysis is to develop effective strategies to improve the security posture of FCEB, CI, maritime, and During each RVA, CISA and the USCG collect data through remote and onsite actions. This data is combined with national threat and vulnerability information to provide organizations with actionable remediation recommendations prioritized by risk of compromise. CISA designed RVAs to identify vulnerabilities threat actors could exploit to compromise network security controls.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-2868 9.4 Critical Barracuda Networks Email Security Gateway (ESG) Appliance Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.