Lucene search

K
cvelistTwcertCVELIST:CVE-2023-48375
HistoryDec 15, 2023 - 7:46 a.m.

CVE-2023-48375 SmartStar Software CWS Web-Base - Broken Access Control

2023-12-1507:46:16
CWE-862
twcert
www.cve.org
3
smartstar software
cws web-base
broken access control
missing authorization
administrator privilege
system operations

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

19.3%

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "CWS Web-Base",
    "vendor": "SmartStar Software",
    "versions": [
      {
        "status": "affected",
        "version": "v10.25"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

19.3%

Related for CVELIST:CVE-2023-48375