Lucene search

K
cveTwcertCVE-2023-25780
HistoryJun 02, 2023 - 11:15 a.m.

CVE-2023-25780

2023-06-0211:15:10
CWE-306
twcert
web.nvd.nist.gov
28
cve-2023-25780
vulnerability
insufficient authentication
status powerbpm
lan attacker
modify substitute agent

CVSS3

5.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.7

Confidence

High

EPSS

0

Percentile

9.0%

It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.

Affected configurations

Nvd
Node
statuspowerbpmMatch2.0
VendorProductVersionCPE
statuspowerbpm2.0cpe:2.3:a:status:powerbpm:2.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Status Internet Co.,Ltd.",
    "product": "PowerBPM",
    "versions": [
      {
        "version": "2.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

5.7

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-25780