NVD disclosure day

Published threat advisories for January 19, 2024

CVE advisoryCRITICAL

CVE-2024-23687

FOLIO mod-data-export-spring Hard-coded Credentials Allow Unauthorized API Access and Data Manipulation.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Hard-coded credentials in FOLIO mod-data-export-spring permit unauthenticated users to access critical APIs, potentially modifying user data, system configurations, and financial records. While the component is part of an internal-facing system, confirmation of its exposure is crucial for understanding potential impact

CVE advisoryCRITICAL

CVE-2023-51947

Improper Access Control in actidata actiNAS SL 2U-8 RDX Allows Unauthenticated Data Reading and Modification.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Improper access control in actidata network storage devices lets unauthenticated attackers read and modify data. This vulnerability could allow unauthorized access and modification of sensitive information. Confirm device usage and network exposure to assess relevance.