{
  "version": "09202026_1325",
  "purpose": "Frozen teaching evidence; asset details are fictional. This is not output from the upstream CVE Prioritizer tool and is not current intelligence after retrieval.",
  "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
  "epss_source": {
    "url": "https://api.first.org/data/v1/epss?cve=CVE-2021-44228%2CCVE-2023-23397%2CCVE-2023-34362%2CCVE-2024-3094%2CCVE-2023-44487",
    "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
    "sha256_full_response": "a5c55ef8aafc564bd8631d58924a8fc0c08c8bb060cf1871018c50267c944572"
  },
  "epss_response_metadata": {
    "status": "OK",
    "status-code": 200,
    "version": "1.0",
    "access": "public",
    "total": 5,
    "offset": 0,
    "limit": 100
  },
  "kev_source": {
    "url": "https://raw.githubusercontent.com/cisagov/kev-data/main/known_exploited_vulnerabilities.json",
    "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
    "sha256_full_response": "7b770a6f5eb1d47a7176ef2f1428594551399912c8f3b5d2bf0f562b7e745e06"
  },
  "kev_metadata": {
    "title": "CISA Catalog of Known Exploited Vulnerabilities",
    "catalogVersion": "2026.09.18",
    "dateReleased": "2026-09-18T19:00:05.0974Z",
    "count": 1716
  },
  "findings": [
    {
      "cve": "CVE-2021-44228",
      "synthetic_asset": {
        "finding": "A",
        "asset": "Fictional internal Java service",
        "affected": "unconfirmed",
        "exposure": "Internal network; package inventory only",
        "context": "Scanner matched a library filename; loaded version and reachable execution path have not been verified."
      },
      "cvss_v3_1": {
        "version": "3.1",
        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "baseScore": 10.0,
        "baseSeverity": "CRITICAL",
        "attackVector": "NETWORK",
        "attackComplexity": "LOW",
        "privilegesRequired": "NONE",
        "userInteraction": "NONE",
        "scope": "CHANGED",
        "confidentialityImpact": "HIGH",
        "integrityImpact": "HIGH",
        "availabilityImpact": "HIGH"
      },
      "cvss_source": "nvd@nist.gov",
      "nvd_last_modified": "2026-08-11T19:33:44.513",
      "nvd_source": {
        "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-44228",
        "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
        "sha256_full_response": "3ea1c0f40fd87ae0a099e2b5614ffe5dbc58ba7813a6a62c58073d7552fa1b6b"
      },
      "epss": {
        "cve": "CVE-2021-44228",
        "epss": "0.999990000",
        "percentile": "1.000000000",
        "date": "2026-09-20"
      },
      "kev_listed_in_snapshot": true,
      "kev_record": {
        "cveID": "CVE-2021-44228",
        "vendorProject": "Apache",
        "product": "Log4j2",
        "vulnerabilityName": "Apache Log4j2 Remote Code Execution Vulnerability",
        "dateAdded": "2021-12-10",
        "shortDescription": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
        "requiredAction": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
        "dueDate": "2021-12-24",
        "knownRansomwareCampaignUse": "Known",
        "forensicTriage": "No",
        "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
        "cwes": [
          "CWE-20",
          "CWE-400",
          "CWE-502"
        ]
      }
    },
    {
      "cve": "CVE-2023-23397",
      "synthetic_asset": {
        "finding": "B",
        "asset": "Fictional finance-team Outlook endpoint",
        "affected": "confirmed in exercise",
        "exposure": "Receives external email",
        "context": "Fictional device inventory confirms affected software. No evidence has been collected to determine whether exploitation occurred."
      },
      "cvss_v3_1": {
        "version": "3.1",
        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "baseScore": 9.8,
        "baseSeverity": "CRITICAL",
        "attackVector": "NETWORK",
        "attackComplexity": "LOW",
        "privilegesRequired": "NONE",
        "userInteraction": "NONE",
        "scope": "UNCHANGED",
        "confidentialityImpact": "HIGH",
        "integrityImpact": "HIGH",
        "availabilityImpact": "HIGH"
      },
      "cvss_source": "nvd@nist.gov",
      "nvd_last_modified": "2026-06-17T05:37:01.380",
      "nvd_source": {
        "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-23397",
        "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
        "sha256_full_response": "f7fd25a3e0c7bce9b3c76bcef68bf719e1a21102b3b6013b377416a1931a156b"
      },
      "epss": {
        "cve": "CVE-2023-23397",
        "epss": "0.974080000",
        "percentile": "0.998960000",
        "date": "2026-09-20"
      },
      "kev_listed_in_snapshot": true,
      "kev_record": {
        "cveID": "CVE-2023-23397",
        "vendorProject": "Microsoft",
        "product": "Office",
        "vulnerabilityName": "Microsoft Office Outlook Privilege Escalation Vulnerability",
        "dateAdded": "2023-03-14",
        "shortDescription": "Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.",
        "requiredAction": "Apply updates per vendor instructions.",
        "dueDate": "2023-04-04",
        "knownRansomwareCampaignUse": "Unknown",
        "forensicTriage": "No",
        "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23397, https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/, ;  https://nvd.nist.gov/vuln/detail/CVE-2023-23397",
        "cwes": [
          "CWE-294"
        ]
      }
    },
    {
      "cve": "CVE-2023-34362",
      "synthetic_asset": {
        "finding": "C",
        "asset": "Fictional public file-transfer server",
        "affected": "confirmed in exercise",
        "exposure": "Public internet",
        "context": "Fictional inventory confirms an affected version and public access. It handles sensitive files; no compensating control is recorded."
      },
      "cvss_v3_1": {
        "version": "3.1",
        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "baseScore": 9.8,
        "baseSeverity": "CRITICAL",
        "attackVector": "NETWORK",
        "attackComplexity": "LOW",
        "privilegesRequired": "NONE",
        "userInteraction": "NONE",
        "scope": "UNCHANGED",
        "confidentialityImpact": "HIGH",
        "integrityImpact": "HIGH",
        "availabilityImpact": "HIGH"
      },
      "cvss_source": "nvd@nist.gov",
      "nvd_last_modified": "2026-06-17T06:03:28.760",
      "nvd_source": {
        "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-34362",
        "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
        "sha256_full_response": "14f3ba4fb7a50401cf6fdf7fc174368239532ac998368f6c12ce3313dc555d95"
      },
      "epss": {
        "cve": "CVE-2023-34362",
        "epss": "0.999340000",
        "percentile": "0.999700000",
        "date": "2026-09-20"
      },
      "kev_listed_in_snapshot": true,
      "kev_record": {
        "cveID": "CVE-2023-34362",
        "vendorProject": "Progress",
        "product": "MOVEit Transfer",
        "vulnerabilityName": "Progress MOVEit Transfer SQL Injection Vulnerability",
        "dateAdded": "2023-06-02",
        "shortDescription": "Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.",
        "requiredAction": "Apply updates per vendor instructions.",
        "dueDate": "2023-06-23",
        "knownRansomwareCampaignUse": "Known",
        "forensicTriage": "No",
        "notes": "This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023.;  https://nvd.nist.gov/vuln/detail/CVE-2023-34362",
        "cwes": [
          "CWE-89"
        ]
      }
    },
    {
      "cve": "CVE-2024-3094",
      "synthetic_asset": {
        "finding": "D",
        "asset": "Fictional Linux build worker",
        "affected": "unconfirmed",
        "exposure": "Internal build network",
        "context": "Scanner matched xz by name only. Distribution package version and vendor advisory applicability are missing. Do not assume all xz installations are affected."
      },
      "cvss_v3_1": {
        "version": "3.1",
        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "baseScore": 10.0,
        "baseSeverity": "CRITICAL",
        "attackVector": "NETWORK",
        "attackComplexity": "LOW",
        "privilegesRequired": "NONE",
        "userInteraction": "NONE",
        "scope": "CHANGED",
        "confidentialityImpact": "HIGH",
        "integrityImpact": "HIGH",
        "availabilityImpact": "HIGH"
      },
      "cvss_source": "nvd@nist.gov",
      "nvd_last_modified": "2026-06-17T07:43:17.830",
      "nvd_source": {
        "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-3094",
        "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
        "sha256_full_response": "2676f2b31ea2e6bc0a7d0d69af365683d38cd021ed710cc5395b5300511b8015"
      },
      "epss": {
        "cve": "CVE-2024-3094",
        "epss": "0.859740000",
        "percentile": "0.997190000",
        "date": "2026-09-20"
      },
      "kev_listed_in_snapshot": false,
      "kev_record": null
    },
    {
      "cve": "CVE-2023-44487",
      "synthetic_asset": {
        "finding": "E",
        "asset": "Fictional public HTTP/2 service",
        "affected": "confirmed in exercise",
        "exposure": "Public internet through a protective edge",
        "context": "A mitigation is recorded, but its coverage and configuration have not been tested. Availability is business-critical."
      },
      "cvss_v3_1": {
        "version": "3.1",
        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
        "baseScore": 7.5,
        "baseSeverity": "HIGH",
        "attackVector": "NETWORK",
        "attackComplexity": "LOW",
        "privilegesRequired": "NONE",
        "userInteraction": "NONE",
        "scope": "UNCHANGED",
        "confidentialityImpact": "NONE",
        "integrityImpact": "NONE",
        "availabilityImpact": "HIGH"
      },
      "cvss_source": "nvd@nist.gov",
      "nvd_last_modified": "2026-08-11T19:37:30.880",
      "nvd_source": {
        "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-44487",
        "retrieved_utc": "2026-09-20T17:27:30.825353+00:00",
        "sha256_full_response": "ef7d23ea0548f2a9b699fa62e6161b2fcd9bd5ca9dc8120ca904d5326e13b582"
      },
      "epss": {
        "cve": "CVE-2023-44487",
        "epss": "0.999990000",
        "percentile": "0.999990000",
        "date": "2026-09-20"
      },
      "kev_listed_in_snapshot": true,
      "kev_record": {
        "cveID": "CVE-2023-44487",
        "vendorProject": "IETF",
        "product": "HTTP/2",
        "vulnerabilityName": "HTTP/2 Rapid Reset Attack Vulnerability",
        "dateAdded": "2023-10-10",
        "shortDescription": "HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).",
        "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "dueDate": "2023-10-31",
        "knownRansomwareCampaignUse": "Unknown",
        "forensicTriage": "No",
        "notes": "This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/;  https://nvd.nist.gov/vuln/detail/CVE-2023-44487",
        "cwes": [
          "CWE-400"
        ]
      }
    }
  ]
}