NVD disclosure day

Published threat advisories for May 28, 2024

CVE advisoryKnown Exploit

CVE-2024-24919

Check Point Gateways Information Disclosure Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Check Point Security Gateways may allow unauthorized access to sensitive information. This impacts organizations using these gateways with Remote Access VPN or Mobile Access. The exposure of data presents a risk to business operations. A security fix is available.

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-35563

CDG Server SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical SQL injection vulnerability exists in CDG-Server software, specifically via the `permissionId` parameter. An unauthenticated attacker could exploit this to manipulate database queries, potentially leading to unauthorized access to or modification of sensitive data. The relevance of this vulnerability hinges

CVE advisoryKnown Exploit

CVE-2024-5274

Google Chrome Code Execution Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Google Chrome's V8 engine allows remote attackers to execute arbitrary code. This type confusion flaw could affect organizations by enabling unauthorized code execution within a sandbox. Prompt action is essential to protect assets and data.

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-35398

TOTOLINK CP900L Stack Overflow via desc Parameter in setMacFilterRules

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical stack overflow vulnerability has been identified in TOTOLINK CP900L devices, stemming from the `setMacFilterRules` function's handling of the `desc` parameter. This flaw could permit attackers to disrupt device operations or potentially gain unauthorized control, impacting device availability and integrity.