Lucene search

K
cvelistNozomiCVELIST:CVE-2023-5937
HistoryMay 15, 2024 - 4:06 p.m.

CVE-2023-5937 Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0

2024-05-1516:06:52
CWE-538
Nozomi
www.cve.org
4
cve-2023-5937
sensitive data exfiltration
unsafe permissions
windows systems
arc configuration files
information disclosure
local attackers

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVSS4

5.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/SC:H/VI:N/SI:H/VA:N/SA:H

AI Score

4.3

Confidence

High

EPSS

0

Percentile

9.0%

On Windows systems, the Arc configuration files resulted to be world-readable.

This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "Arc",
    "vendor": "Nozomi Networks",
    "versions": [
      {
        "lessThan": "1.6.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

3.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CVSS4

5.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/SC:H/VI:N/SI:H/VA:N/SA:H

AI Score

4.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2023-5937