Lucene search

K
cve[email protected]CVE-2023-24476
HistoryJun 07, 2023 - 10:15 p.m.

CVE-2023-24476

2023-06-0722:15:09
CWE-285
web.nvd.nist.gov
17
cve-2023-24476
local access
traffic recording
request resend
authentication bypass

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

An attacker with local access to the machine could record the traffic,
which could allow them to resend requests without the server
authenticating that the user or session are valid.

Affected configurations

NVD
Node
ptcvuforia_studioRange<9.9

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Vuforia Studio",
    "vendor": "PTC ",
    "versions": [
      {
        "lessThan": "9.9",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

Related for CVE-2023-24476