NVD disclosure day

Published threat advisories for November 22, 2022

CVE advisoryCRITICAL

CVE-2022-44194

Netgear R7000P Firmware Buffer Overflow Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A buffer overflow vulnerability exists in Netgear R7000P devices. An unauthenticated attacker can exploit this by sending specially crafted requests related to DNS settings, potentially leading to arbitrary code execution and device compromise. This could impact network services and device configuration. The relevance

CVE advisoryCRITICAL

CVE-2022-42989

Sankhya ERP Caixa de Entrada Cross-Site Scripting Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A cross-site scripting vulnerability exists in an ERP system component, potentially allowing for script injection. If reachable, this could impact user sessions and displayed data. While the specific technology and its reachability are uncertain, such vulnerabilities in ERP systems warrant attention due to the critical

CVE advisoryKnown Exploit

CVE-2022-41223

Mitel MiVoice Connect Code Injection Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the MiVoice Connect Director database component allows an authenticated attacker to inject code. This could lead to unauthorized access and disruption of services. Affected organizations should apply vendor updates to mitigate business risk.

• CISA KEV

CVE advisoryCRITICAL

CVE-2022-40842

ndk-design NdkAdvancedCustomizationFields SSRF Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A server-side request forgery vulnerability exists in NdkAdvancedCustomizationFields up to version 3.5.0, allowing unauthenticated attackers to trick the server into making requests to arbitrary internal or external resources. This could potentially expose sensitive information or impact service availability.

CVE advisoryKnown Exploit

CVE-2022-40765

Mitel MiVoice Connect Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated attacker with internal network access can exploit a command injection vulnerability in Mitel MiVoice Connect. This could result in unauthorized command execution, impacting affected systems and potentially leading to data compromise or disruption. The business risk necessitates prompt attention to miti

• CISA KEV

CVE advisoryCRITICAL

CVE-2022-36179

FusionDirectory Improper Session Handling Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

FusionDirectory 1.3 contains a critical improper session handling vulnerability. If reachable over a network, an attacker could exploit this flaw to gain unauthorized access and potentially control sensitive directory information. Confirmation of the technology's presence and its network exposure is necessary to unders