NVD disclosure day

Published threat advisories for April 4, 2023

CVE advisoryCRITICAL

CVE-2021-28235

Etcd Authentication Bypass Allows Privilege Escalation

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authentication vulnerability in Etcd-io allows remote attackers to escalate privileges via the debug function. This could potentially lead to unauthorized access or modifications to system data, impacting integrity and availability. Determining if Etcd is used and exposed is crucial for assessing risk.

CVE advisoryCRITICAL

CVE-2020-29312

Zend Framework unserialize Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A flaw in Zend Framework's `unserialize` function could allow remote code execution. Although the framework is deprecated and there are disputes about the vulnerability's specifics, it's important to confirm if this technology is in use and exposed to potential threats.

CVE advisoryKnown Exploit

CVE-2023-1671

Sophos Web Appliance: Command Injection Risk

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability in Sophos Web Appliance allows attackers to execute arbitrary code. This can lead to system compromise and potential data breaches, impacting business operations. Organisations using affected versions should apply vendor updates.

• CISA KEV