5.4
CVE-2023-23568
- EPSS 0.07%
- Veröffentlicht 25.07.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:26
- Quelle disclosures@gallagher.com
- CVE-Watchlists
- Unerledigt
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL 8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to vEL8.50.2831 (MR8), all versions vEL8.40 and prior
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gallagher ≫ Command Centre Version <= 8.40.2216
Gallagher ≫ Command Centre Version >= 8.50 < 8.50.2831
Gallagher ≫ Command Centre Version >= 8.60 < 8.60.2347
Gallagher ≫ Command Centre Version >= 8.70 < 8.70.2185
Gallagher ≫ Command Centre Version >= 8.80 < 8.80.1192
Gallagher ≫ Command Centre Version >= 8.90 < 8.90.1318
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.218 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
| disclosures@gallagher.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.