NVD disclosure day

Published threat advisories for August 8, 2023

CVE advisoryKnown Exploit

CVE-2023-38180

.NET and Visual Studio Denial of Service Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A denial-of-service vulnerability affects .NET and Visual Studio, allowing attackers to disrupt services. This matters because it can make systems unresponsive, leading to business downtime. The risk involves service unavailability for legitimate users.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-3386

Attacker can steal sensitive data or control the tracking system

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can access the a2 Camera Trap Tracking System through its web interface to compromise the backend database. This could allow them to steal, change, or delete sensitive monitoring data, leading to a loss of proprietary information.

CVE advisoryCRITICAL

CVE-2023-3651

Digital Ant E-Commerce Software can be exploited to steal customer data or disrupt services

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Digital Ant E-Commerce Software has a critical flaw allowing unauthorized access to steal or alter sensitive customer data. This issue is exploitable over the internet without needing a login, making your business a potential target.

CVE advisoryCRITICAL

CVE-2023-3716

Attacker can steal customer data or disrupt Oduyo Online Collection Software by tricking it into running malicious database commands.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in Oduyo Online Collection Software could let attackers steal sensitive data or disrupt services by sending malicious commands to the database. Update now to protect your financial information.