Lucene search

K
cveMitreCVE-2023-43176
HistoryOct 03, 2023 - 9:15 p.m.

CVE-2023-43176

2023-10-0321:15:10
CWE-502
mitre
web.nvd.nist.gov
25
cve-2023-43176
deserialization vulnerability
afterlogic aurora files
arbitrary code execution
sabredav file

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

50.5%

A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.

Affected configurations

Nvd
Node
afterlogicaurora_filesMatch9.7.3
VendorProductVersionCPE
afterlogicaurora_files9.7.3cpe:2.3:a:afterlogic:aurora_files:9.7.3:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

50.5%

Related for CVE-2023-43176