Lucene search

K
cveMitreCVE-2023-23130
HistoryFeb 01, 2023 - 2:15 p.m.

CVE-2023-23130

2023-02-0114:15:09
CWE-319
mitre
web.nvd.nist.gov
28
cve-2023-23130
connectwise automate
cleartext authentication
vulnerability
security issue

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

51.9%

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor’s position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

Affected configurations

Nvd
Node
connectwiseautomateMatch2022.11
VendorProductVersionCPE
connectwiseautomate2022.11cpe:2.3:a:connectwise:automate:2022.11:*:*:*:*:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

51.9%

Related for CVE-2023-23130