Lucene search

K
cve[email protected]CVE-2023-38544
HistoryNov 15, 2023 - 12:15 a.m.

CVE-2023-38544

2023-11-1500:15:08
web.nvd.nist.gov
4
cve-2023-38544
logged in user
system-wide configuration
unauthorized changes
integrity compromise
network security

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.

Affected configurations

NVD
Node
ivantisecure_access_clientMatch22.2r1
OR
ivantisecure_access_clientMatch22.3r1
OR
ivantisecure_access_clientMatch22.3r2
OR
ivantisecure_access_clientMatch22.3r3
AND
linuxlinux_kernelMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "vendor": "Ivanti",
    "product": "Secure Access Linux",
    "versions": [
      {
        "version": "22.6.1",
        "status": "affected",
        "lessThan": "22.6.1",
        "versionType": "semver"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

5.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for CVE-2023-38544