Lucene search

K
cveTwcertCVE-2023-48375
HistoryDec 15, 2023 - 8:15 a.m.

CVE-2023-48375

2023-12-1508:15:45
CWE-862
twcert
web.nvd.nist.gov
10
smartstar software
cws
web-based integration platform
missing authorization
vulnerability
cve-2023-48375
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

19.3%

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

Affected configurations

Nvd
Node
csharpcws_collaborative_development_platformMatch10.25
VendorProductVersionCPE
csharpcws_collaborative_development_platform10.25cpe:2.3:a:csharp:cws_collaborative_development_platform:10.25:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "CWS Web-Base",
    "vendor": "SmartStar Software",
    "versions": [
      {
        "status": "affected",
        "version": "v10.25"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

19.3%

Related for CVE-2023-48375