NVD disclosure day

Published threat advisories for January 28, 2022

CVE advisoryKnown Exploit

CVE-2021-4034

Polkit pkexec Local Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the polkit pkexec utility allows local users to gain administrative privileges. This flaw can enable an unprivileged user to execute arbitrary code, potentially impacting system security and data integrity. Organizations should review their systems for this vulnerability.

• CISA KEV

CVE advisoryCRITICAL

CVE-2021-44971

Tenda AC15 and AC5 Authentication Bypass and Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Multiple Tenda devices are susceptible to an authentication bypass vulnerability that an attacker could exploit to gain sensitive information and potentially execute commands remotely. This issue is concerning because these network gateway devices are often at the network perimeter, increasing the risk of external expl