NVD disclosure day

Published threat advisories for November 29, 2023

CVE advisoryKnown Exploit

CVE-2023-6345

Google Chrome Sandbox Escape Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in the Skia component of Google Chrome allows a compromised renderer process to potentially escape the sandbox. This could grant attackers elevated privileges. The CISA Known Exploited Vulnerabilities catalog lists this CVE, indicating active exploitation and a need for immediate remediation.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-23325

Zumtobel Netlink Command Injection Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical command injection vulnerability exists in Zumtobel Netlink firmware via the NetHostname parameter, allowing unauthenticated remote attackers to execute arbitrary commands. This could lead to unauthorized system control and modification of device behavior. Understanding the potential exposure and relevance to

CVE advisoryCRITICAL

CVE-2023-23324

Zumtobel Netlink CCD Hardcoded Administrator Credentials Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Zumtobel Netlink lighting control firmware due to hardcoded administrator credentials. This allows unauthenticated attackers to gain administrative control over the lighting system, potentially altering behavior or disrupting operations. Confirming relevance and exposure is crucial du