NVD disclosure day

Published threat advisories for August 21, 2023

CVE advisoryKnown Exploit

CVE-2023-38035

Ivanti Sentry Authentication Bypass.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Ivanti MobileIron Sentry affects its administrative portal, allowing attackers to bypass authentication. This poses a business risk by potentially granting unauthorized access to administrative functions. Affected organizations should identify all instances of the product and implement vendor solutio

• CISA KEV

CVE advisoryCRITICAL

CVE-2020-28715

LeEco LeTV X43 kdmserver Arbitrary Code Execution and Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the kdmserver service of LeEco LeTV X43, enabling unauthenticated attackers to execute arbitrary code, escalate privileges, or cause denial of service via network requests. This affects consumer smart television technology.

CVE advisoryCRITICAL

CVE-2023-39809

NVK iBSG Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical command injection vulnerability exists in NVK's Intelligent Broadband Subscriber Gateway. This flaw, reachable via the network, could allow an unauthenticated attacker to execute arbitrary commands on the affected system. This could compromise network operations and security.

CVE advisoryCRITICAL

CVE-2023-39808

NVK iBSG v3.5 Hardcoded Root Password SSH Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in NVK's Intelligent Broadband Subscriber Gateway software, stemming from a hardcoded root password. This flaw allows unauthenticated attackers to gain root-level access via the SSH service, potentially leading to unauthorized system control, data access, or service disruption. This issu

CVE advisoryCRITICAL

CVE-2023-39807

NVK iBSG SQL Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical SQL injection vulnerability exists in the NVK Intelligent Broadband Subscriber Gateway's user registration portal, allowing attackers to execute arbitrary SQL commands and potentially access, modify, or delete sensitive data. This issue is relevant due to the gateway's common deployment as an internet-facing