NVD disclosure day

Published threat advisories for March 10, 2020

CVE advisoryKnown Exploit

CVE-2020-6207

SAP Solution Manager Unauthenticated Service Compromise.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in SAP Solution Manager allows unauthenticated access, potentially leading to the compromise of all connected SMDAgents. This impacts system integrity and data security. The business risk is high due to the potential for widespread system compromise.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-0069

Mediatek Driver Vulnerability Allows Local Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Mediatek Command Queue driver could allow a local attacker to escalate privileges on affected Android systems. This could impact device security and data integrity. The realistic business risk is associated with unauthorized access and control of the affected systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-0041

Android Kernel Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability affects the Android kernel, specifically the binder driver, allowing local privilege escalation. It matters because it can lead to unauthorized system control and data compromise. The realistic business risk includes potential unauthorized access to sensitive information and disruption of services.

• CISA KEV