NVD disclosure day

Published threat advisories for October 28, 2020

CVE advisoryKnown Exploit

CVE-2018-19953

QNAP QTS Cross-Site Scripting Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A cross-site scripting vulnerability affects QNAP QTS systems, enabling remote attackers to inject malicious code and potentially compromise system integrity. The risk involves unauthorized code execution, impacting data and operations. Organizations should identify and protect affected systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2018-19943

QNAP QTS Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A cross-site scripting flaw in QNAP QTS allows remote attackers to inject malicious code, potentially impacting system integrity and data confidentiality for affected organizations. This external vulnerability has been observed in the wild, posing a business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-8260

Pulse Connect Secure Arbitrary Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authenticated attacker can exploit a flaw in the Pulse Connect Secure admin web interface, allowing for arbitrary code execution through uncontrolled gzip extraction. This presents a business risk of unauthorized system access and data compromise.

• CISA KEV