AWS Security Advisories · January 2021 — AWS Security Advisories
24 advisories 66 CVEs 4 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2021-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 4 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2021-1478

ALAS · AL1ExploitedCISA KEV listedImportant2021-01-26

ALAS-2021-1478: sudo (important)

CVEs:CVE-2021-3156

Affected products

ProductStatusVendorPackageEcosystem
sudo affected Amazon sudo
Upstream advisory

ALAS-2021-1465

ALAS · AL1PoC exploitImportant2021-01-15

ALAS-2021-1465: net-snmp (important)

CVEs:CVE-2020-15862

Affected products

ProductStatusVendorPackageEcosystem
net-snmp affected Amazon net-snmp
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.