Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-51750
HistoryJan 11, 2024 - 12:00 a.m.

CVE-2023-51750

2024-01-1100:00:00
mitre
github.com
scalefusion
10.5.2
edge application
user limit
bypass
file downloads
windows device profile
website allow-listing rules
cve-2023-51750

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor’s position is “Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules.”

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:scalefusion:scalefusion:10.5.2:*:*:*:*:windows:*:*"
    ],
    "vendor": "scalefusion",
    "product": "scalefusion",
    "versions": [
      {
        "status": "affected",
        "version": "10.5.2"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-51750