6.5
CVE-2023-3425
- EPSS 0.15%
- Veröffentlicht 25.08.2023 09:15:08
- Zuletzt bearbeitet 23.02.2026 09:16:15
- Quelle security@m-files.com
- CVE-Watchlists
- Unerledigt
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
M-files ≫ Classic Web SwEditionlts Version < 23.2
M-files ≫ Classic Web SwEdition- Version < 23.6.12695.3
M-files ≫ Classic Web Version23.2 Update- SwEditionlts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.354 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| security@m-files.com | 6.5 | 2.2 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.