Nov 13, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Juniper Junos OS: 5 CVEs added to CISA KEV today.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-47246 SysAid Server Path Traversal

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Remote code execution exposure

SysAid Server Code Execution is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2023-31403 Sap Business One privilege escalation

  • CVSS 9.6
  • Potential privilege escalation to admin/root

New critical Sap Business One privilege escalation (CVSS 9.6) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

High-risk exposure

CVE-2023-6097 Icssolution Ics Business Manager SQL Injection

  • CVSS 9.4

New high-severity Icssolution Ics Business Manager SQL Injection — watch for exploit drops and scanner noise in the first 72 hours after disclosure.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Juniper Junos OS SRX Series Missing Authentication for Critical Function

Juniper Junos OS EX Series PHP External Variable Modification

Juniper Junos OS EX Series and SRX Series PHP External Variable Modification

Juniper Junos OS SRX Series Missing Authentication for Critical Function

Juniper Junos OS EX Series Missing Authentication for Critical Function

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2023-31403 CVSS 9.6

SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder.

CVE-2023-6097 CVSS 9.4

A SQL injection vulnerability has been found in ICS Business Manager, affecting version 7.06.0028.7089.

View critical disclosures

cvelogic Threat Intelligence