NVD disclosure day

Published threat advisories for July 1, 2024

CVE advisoryKnown Exploit

CVE-2024-38475

Apache HTTP Server: URL Mapping Vulnerability Allows Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A flaw in Apache HTTP Server's mod_rewrite allows attackers to map URLs to unintended filesystem locations, potentially leading to code execution or source code disclosure. This poses a business risk through unauthorized access and sensitive data exposure.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-20399

Cisco NX-OS Command Injection Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Cisco NX-OS allows authenticated administrators to execute arbitrary commands as root. This impacts organizations by potentially compromising operating system control on affected devices. Business risk is present for organizations with these systems.

• CISA KEV