7.5
CVE-2023-6150
- EPSS 0.6%
- Veröffentlicht 28.11.2023 10:15:07
- Zuletzt bearbeitet 20.05.2026 14:16:35
- Quelle iletisim@usom.gov.tr
- CVE-Watchlists
- Unerledigt
Information Disclosure in Eskom E-municipality
Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided by Users. This issue affects e-municipality module: before v.105.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eskom ≫ E-belediye Version < 105
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.438 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| iletisim@usom.gov.tr | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-648 Incorrect Use of Privileged APIs
The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.
https://www.usom.gov.tr/bildirim/tr-23-0664
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0664