Lucene search

K
cveHackeroneCVE-2023-41718
HistoryNov 15, 2023 - 12:15 a.m.

CVE-2023-41718

2023-11-1500:15:08
hackerone
web.nvd.nist.gov
17
cve-2023-41718
security
unauthorized access
privilege escalation
process flow

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.0%

When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.

Affected configurations

Nvd
Vulners
Node
microsoftwindowsMatch-
AND
ivantisecure_access_clientMatch22.2r1
OR
ivantisecure_access_clientMatch22.3r1
OR
ivantisecure_access_clientMatch22.3r2
OR
ivantisecure_access_clientMatch22.3r3
VendorProductVersionCPE
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
ivantisecure_access_client22.2cpe:2.3:a:ivanti:secure_access_client:22.2:r1:*:*:*:*:*:*
ivantisecure_access_client22.3cpe:2.3:a:ivanti:secure_access_client:22.3:r1:*:*:*:*:*:*
ivantisecure_access_client22.3cpe:2.3:a:ivanti:secure_access_client:22.3:r2:*:*:*:*:*:*
ivantisecure_access_client22.3cpe:2.3:a:ivanti:secure_access_client:22.3:r3:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "vendor": "Ivanti",
    "product": "Secure Access",
    "versions": [
      {
        "version": "22.6.1.1",
        "status": "affected",
        "lessThan": "22.6.1.1",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-41718