NVD disclosure day

Published threat advisories for November 19, 2024

CVE advisoryCRITICAL

CVE-2024-52714

Tenda AC6 Firmware Buffer Overflow in fromSetSysTime

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability exists in Tenda AC6 router firmware within the `fromSetSysTime` function. This flaw could allow unauthenticated remote attackers to execute arbitrary code, potentially leading to complete device compromise. Because these routers are often internet-facing, this vulnerability pose

CVE advisoryCRITICAL

CVE-2024-42450

Versa Director Default Credentials Allow Database Access and Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An unauthenticated attacker can access Versa Director's PostgreSQL database due to a default common password and network exposure, potentially leading to administrative control or privilege escalation. This could expose operational and configuration data. The relevance and exposure need to be confirmed.

CVE advisoryKnown Exploit

CVE-2024-50302

Linux kernel could allow internal attacker to access sensitive system data

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An internal attacker can exploit a memory flaw in the Linux kernel by mimicking a connected hardware device. This allows them to read restricted system memory to steal cryptographic keys and credentials, which could let them bypass security controls and compromise sensitive company data.

• CISA KEV