Lucene search

K
cvelistCisa-cgCVELIST:CVE-2023-6376
HistoryNov 30, 2023 - 5:55 p.m.

CVE-2023-6376 Henschen & Associates court document management software cache uses predictable file names

2023-11-3017:55:13
CWE-330
cisa-cg
www.cve.org
6
henschen & associates
court document management
cache
predictable file names
remote attacker
restricted access

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

54.5%

Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "product": "court document management software",
    "vendor": "Henschen & Associates",
    "versions": [
      {
        "lessThan": "~2023-11-22",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

54.5%

Related for CVELIST:CVE-2023-6376