7.1
CVE-2023-46669
- EPSS 0.08%
- Veröffentlicht 01.05.2025 12:59:49
- Zuletzt bearbeitet 01.10.2025 19:31:08
- Quelle bressers@elastic.co
- CVE-Watchlists
- Unerledigt
Elastic Agent / Elastic Endpoint Security local API key disclosure
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elastic ≫ Elastic Agent Version < 8.15.0
Elastic ≫ Endpoint Security Version < 8.15.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.24 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
| bressers@elastic.co | 6.2 | 2.5 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.