NVD disclosure day

Published threat advisories for August 29, 2023

CVE advisoryKnown Exploit

CVE-2023-41266

Qlik Sense Path Traversal Vulnerability Allows Unauthorized Access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in Qlik Sense Enterprise for Windows allowed unauthenticated remote attackers to create anonymous sessions. This could enable attackers to send requests to unauthorized endpoints, potentially leading to unauthorized access to data or system functions. This vulnerability is known to be exp

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-41265

Qlik Sense Privilege Escalation via HTTP Tunneling

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An HTTP Request Tunneling vulnerability in Qlik Sense Enterprise for Windows allows attackers to escalate privileges. This could enable unauthorized command execution on the backend server, impacting data and operations. Affected organizations should apply vendor updates.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-4346

KNX Connection Authorization Lockout Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

KNX devices with Connection Authorization Option 1 can be locked by attackers with network or physical access, preventing user access. The vulnerability allows attackers to purge devices and set a new password without a reset option. Its relevance depends on whether this technology is used in your environment and its n

• CISA KEV

CVE advisoryCRITICAL

CVE-2021-3262

TripSpark NovusEDU and VEO Transportation SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

TripSpark NovusEDU and VEO Transportation software improperly handles user input in search queries, allowing SQL injection. This could lead to unauthorized access, modification, or deletion of sensitive student data. Confirmation of affected versions and network exposure is needed to understand potential risks.