NVD disclosure day

Published threat advisories for August 9, 2023

CVE advisoryCRITICAL

CVE-2023-33468

Kramer VIA Devices Remote Code Extraction Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in KramerAV VIA Connect and VIA Go devices allows remote extraction of connection confirmation codes. This bypasses the need for physical screen access, potentially enabling unauthorized remote manipulation of the device. The issue is relevant for collaboration and presentation device owners.

CVE advisoryCRITICAL

CVE-2023-39004

OPNsense Configuration Directory Insecure Permissions Allow Sensitive Information Access and Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Insecure permissions in OPNsense's configuration directory allow attackers to access sensitive information like hashed passwords, potentially leading to privilege escalation. This affects network access and critical system data. Verify relevance and assess potential exposure.

CVE advisoryCRITICAL

CVE-2023-3632

Kunduz Homework Helper app could allow external attacker to gain unauthorized access.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can exploit a flaw in the Kunduz Homework Helper app to bypass login protections. This allows them to impersonate users, access sensitive student files, and alter account data, risking the exposure of private customer information.