Lucene search

K
nvd[email protected]NVD:CVE-2023-38354
HistorySep 19, 2023 - 4:15 p.m.

CVE-2023-38354

2023-09-1916:15:11
CWE-295
web.nvd.nist.gov
minitool shadow maker
cve-2023-38354
remote code execution
installation process
man in the middle attack

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.3%

MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

Affected configurations

Nvd
Node
minitoolshadowmakerMatch4.1
VendorProductVersionCPE
minitoolshadowmaker4.1cpe:2.3:a:minitool:shadowmaker:4.1:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.3%

Related for NVD:CVE-2023-38354