6.5
CVE-2023-33368
- EPSS 0.16%
- Veröffentlicht 03.08.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Assaabloy ≫ Control Id Idsecure Version <= 4.7.26.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.373 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.