Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-21980
HistoryApr 18, 2023 - 8:15 p.m.

Design/Logic Flaw

2023-04-1820:15:00
PRIOn knowledge base
www.prio-n.com
149
mysql server
oracle mysql
vulnerability
network access
takeover
cvss 3.1

6.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.3%

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).

CPENameOperatorVersion
mysqlge8.0.0
mysqlle8.0.32
mysqlge5.0.0
mysqlle5.7.41