Lucene search

K
nvd[email protected]NVD:CVE-2023-48375
HistoryDec 15, 2023 - 8:15 a.m.

CVE-2023-48375

2023-12-1508:15:45
CWE-862
web.nvd.nist.gov
1
smartstar software cws
vulnerability
unauthorized access
missing authorization
administrator privilege
arbitrary system operations
disrupting service

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.3%

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

Affected configurations

Nvd
Node
csharpcws_collaborative_development_platformMatch10.25
VendorProductVersionCPE
csharpcws_collaborative_development_platform10.25cpe:2.3:a:csharp:cws_collaborative_development_platform:10.25:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.3%

Related for NVD:CVE-2023-48375