NVD disclosure day

Published threat advisories for March 24, 2023

CVE advisoryCRITICAL

CVE-2022-45597

ComponentSpace SAML Missing SSL Certificate Validation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in ComponentSpace SAML involves missing SSL certificate validation, which could allow an attacker to impersonate trusted parties or intercept sensitive information. The vendor does not consider this a vulnerability, stating that certificates are exchanged in a controlled manner. However, this technology

CVE advisoryKnown Exploit

CVE-2023-20963

Android WorkSource Parcel Mismatch Leads to Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Android's WorkSource component could allow for local privilege escalation without user interaction. This impacts affected Android systems by enabling unauthorized access and modification of data and functions, posing a business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-42948

Cobalt Strike UI Vulnerability Allows Remote Code Execution.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Cobalt Strike user interface that allows for remote code execution. Attackers can exploit this by injecting specially crafted HTML, potentially impacting data confidentiality and operational integrity, posing a business risk.

• CISA KEV