NVD disclosure day

Published threat advisories for June 27, 2024

CVE advisoryCRITICAL

CVE-2024-6127

Empire Path Traversal Leading to Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A path traversal vulnerability in BC Security Empire may allow unauthenticated remote attackers to execute code over HTTP. This affects a command-and-control framework, potentially enabling unauthorized control of systems if internet-facing components are reachable.

CVE advisoryCRITICAL

CVE-2024-35260

Microsoft Dataverse Untrusted Search Path Code Execution

Halo Surface Signal: 3 out of 5 — possibly public-facing.

An untrusted search path vulnerability in Microsoft Dataverse allows an authenticated attacker to execute code over a network. This could lead to unauthorized code execution on systems that host or interact with Dataverse services, potentially impacting business operations. Organizations using this technology should co

CVE advisoryCRITICAL

CVE-2024-1107

Travel Apps Authorization Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authorization bypass vulnerability in Travel APPS may allow unauthorized access to sensitive data and system functions. This could impact organizations by exposing confidential information and potentially disrupting operations. The vulnerability could be exploited by unauthenticated attackers.

CVE advisoryCRITICAL

CVE-2024-0949

Elektraweb Authentication Bypass Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Elektraweb allows authentication bypass, potentially exposing systems and data to unauthorized access. The risk to organizations includes unauthorized access to sensitive information and compromised business functions. Affected systems and data integrity may be impacted.

CVE advisoryCRITICAL

CVE-2024-0947

Elektraweb: Session Credential Manipulation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Elektraweb allows attackers to falsify session credentials by manipulating cookies. This could lead to unauthorized access and data modification, posing a risk to affected organizations and their data. Mitigation steps include identifying affected systems and applying vendor updates.