Nov 13, 2023 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- Juniper Junos OS: 5 CVEs added to CISA KEV today.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2023-47246
SysAid Server Path Traversal
- Actively exploited (CISA KEV)
- Listed on CISA KEV
- Remote code execution exposure
SysAid Server Code Execution is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVE-2023-31403
Sap Business One privilege escalation
- CVSS 9.6
- Potential privilege escalation to admin/root
New critical Sap Business One privilege escalation (CVSS 9.6) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
High-risk exposure
CVE-2023-6097
Icssolution Ics Business Manager SQL Injection
New high-severity Icssolution Ics Business Manager SQL Injection — watch for exploit drops and scanner noise in the first 72 hours after disclosure.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
SysAid Server Path Traversal
Juniper Junos OS SRX Series Missing Authentication for Critical Function
Juniper Junos OS EX Series PHP External Variable Modification
Juniper Junos OS EX Series and SRX Series PHP External Variable Modification
Juniper Junos OS SRX Series Missing Authentication for Critical Function
Juniper Junos OS EX Series Missing Authentication for Critical Function
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder.
A SQL injection vulnerability has been found in ICS Business Manager, affecting version 7.06.0028.7089.
View critical disclosures
cvelogic
Threat Intelligence