Lucene search

K
cvelistSecomeaCVELIST:CVE-2023-0317
HistoryApr 19, 2023 - 11:57 a.m.

CVE-2023-0317 GateManager debug interface is included in non-debug builds

2023-04-1911:57:46
CWE-420
Secomea
www.cve.org
5
cve-2023-0317
gatemanager
alternate channel
system administrator
sensitive information
vulnerability

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

24.1%

Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "GateManager",
    "vendor": "Secomea",
    "versions": [
      {
        "lessThan": "10.1",
        "status": "affected",
        "version": "10.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

24.1%

Related for CVELIST:CVE-2023-0317