NVD disclosure day

Published threat advisories for April 13, 2023

CVE advisoryCRITICAL

CVE-2023-27667

Auto Dealer Management System SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in the Auto Dealer Management System, enabling unauthenticated attackers to inject malicious SQL commands over the network. This could lead to unauthorized access, modification, or deletion of sensitive dealer and customer data. Confirming the presence and exposure of this

CVE advisoryCRITICAL

CVE-2023-27812

BloofoxCMS Arbitrary File Deletion Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file deletion vulnerability exists in bloofox content management software, allowing unauthenticated attackers to delete files remotely. If reachable, this could impact data integrity and system availability. Confirmation of its presence and exposure within our environment is the primary concern.

CVE advisoryKnown Exploit

CVE-2023-20118

Cisco Small Business Routers Command Execution Risk

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Cisco Small Business Routers could allow an authenticated attacker to execute arbitrary commands and access unauthorized data. Cisco will not release software updates for this issue. This presents a risk to organizations using affected devices.

• CISA KEV