4.3
CVE-2023-2622
- EPSS 0.13%
- Veröffentlicht 01.11.2023 03:15:07
- Zuletzt bearbeitet 21.11.2024 07:58:57
- Quelle cybersecurity@hitachienergy.co
- Teams Watchlist Login
- Unerledigt Login
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachienergy ≫ Modular Advanced Control For Hvdc Version >= 7.10.0.0 <= 7.18.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.339 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
cybersecurity@hitachienergy.com | 2.7 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.