NVD disclosure day

Published threat advisories for September 15, 2023

CVE advisoryCRITICAL

CVE-2023-4835

CF Software Oil Management Software could allow external attacker to access sensitive data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can manipulate CF Software Oil Management Software to access its underlying database. This allows them to steal admin credentials, tamper with inventory and transaction records, or gain unauthorized control over systems managing critical resource distribution.

CVE advisoryCRITICAL

CVE-2023-4662

Saphira Connect allows attackers to gain unauthorized control of systems over the internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can target Saphira Connect with malicious commands that run with excessive permissions. This can allow them to gain complete administrative control of the server, potentially exposing sensitive corporate data and allowing unauthorized access to the broader business network.

CVE advisoryCRITICAL

CVE-2023-4661

Saphira Connect lets attackers steal customer data or control the system.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can target Saphira Connect to bypass security and steal sensitive database records, including user credentials. This matters because it could allow the attacker to modify application data and gain full unauthorized control over the system.

CVE advisoryCRITICAL

CVE-2023-4670

Innosa Probbys allows attackers to take control or disrupt services

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in Innosa Probbys to access and modify sensitive database information. This could allow them to expose credentials and gain administrative control over the system, putting business operations and sensitive data at risk.

CVE advisoryCRITICAL

CVE-2023-4830

Signalix allows attackers to take control of systems, access sensitive files, and disrupt services.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can exploit a flaw in Tura Signalix to bypass security controls and access sensitive database records. This could allow them to steal confidential files and gain full administrative control, threatening critical business operations and network security.