NVD disclosure day

Published threat advisories for September 5, 2023

CVE advisoryCRITICAL

CVE-2023-4178

Neutron Smart VMS could allow external attacker to bypass security and access the system.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can bypass login security on Neutron Smart VMS to gain full control of the system. This allows them to view live surveillance feeds, delete recorded video logs, and alter configurations, compromising the physical security of our facilities.

CVE advisoryCRITICAL

CVE-2023-4034

Attacker can steal sensitive data or control Smartrise Document Management System over the internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can bypass security controls in the Smartrise Document Management System. This allows them to steal administrative credentials and proprietary company documents, potentially leading to widespread data theft and unauthorized access to other areas of the network.

CVE advisoryCRITICAL

CVE-2023-35068

Attacker can steal sensitive data or take control of BMA Personnel Tracking Systems.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit the BMA Personnel Tracking System to manipulate its database. This could allow them to view, change, or delete sensitive employee records, resulting in the unauthorized access or loss of confidential personnel information.

CVE advisoryCRITICAL

CVE-2023-35065

Osoft Paint Production Management flaw lets attackers steal data or take control.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can take advantage of Osoft Paint Production Management to steal sensitive production records and administrative credentials. This exposes critical business information and could lead to a full compromise of the system.

CVE advisoryHIGH

CVE-2023-3375

Bookreen allows attackers to take control of systems by uploading malicious files.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker could exploit Unisign Bookreen by uploading a malicious file, allowing them to run system commands and potentially gain unauthorized control. This matters because it could lead to complete compromise of the affected system.

CVE advisoryCRITICAL

CVE-2023-3374

Bookreen lets attackers take full control of systems without access.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An internal attacker with existing access to Unisign Bookreen could trick the system into granting them full administrative rights. This creates a significant risk by enabling unauthorized access to critical system settings, which could lead to full control over the platform.