NVD disclosure day

Published threat advisories for June 17, 2024

CVE advisoryCRITICAL

CVE-2023-37057

Unionman Jlink AX1800 Authentication Bypass Remote Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Unionman Technology Co. Ltd Jlink AX1800 devices allows remote attackers to execute arbitrary code via the router's authentication mechanism. This could lead to device compromise. The extent of this issue depends on whether these devices are present in the environment.

CVE advisoryCRITICAL

CVE-2024-36543

STRIMZI Kafka Connect API Access Control Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An unauthenticated attacker can exploit incorrect access control in the Kafka Connect REST API to cause service denial, mirror topic content, and steal Kafka credentials. This vulnerability impacts the STRIMZI Project and requires assessing the reachability and relevance of the affected API.

CVE advisoryKnown Exploit

CVE-2024-6047

GeoVision Devices Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Certain GeoVision devices are vulnerable to remote command execution due to improper user input filtering. This poses a business risk to affected systems and data by allowing unauthorized control. <hr> Certain GeoVision devices have a vulnerability allowing unauthenticated remote attackers to execute system commands. T

• CISA KEV