Lucene search

K
vulnrichmentIllumioVULNRICHMENT:CVE-2023-5183
HistorySep 26, 2023 - 9:29 p.m.

CVE-2023-5183 Authenticated RCE due to unsafe JSON deserialization

2023-09-2621:29:36
CWE-502
Illumio
github.com
cve-2023-5183
authenticated rce
illumio pce
json deserialization

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.4

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:illumio:core_policy_compute_engine:*:*:*:*:*:*:*:*"
    ],
    "vendor": "illumio",
    "product": "core_policy_compute_engine",
    "versions": [
      {
        "status": "affected",
        "version": "19.3.0",
        "versionType": "custom",
        "lessThanOrEqual": "19.3.6"
      },
      {
        "status": "affected",
        "version": "21.2.0",
        "versionType": "custom",
        "lessThanOrEqual": "21.2.7"
      },
      {
        "status": "affected",
        "version": "21.5.0",
        "versionType": "custom",
        "lessThanOrEqual": "21.5.35"
      },
      {
        "status": "affected",
        "version": "22.2.0",
        "versionType": "custom",
        "lessThanOrEqual": "22.2.41"
      },
      {
        "status": "affected",
        "version": "22.5.0",
        "versionType": "custom",
        "lessThanOrEqual": "22.5.30"
      },
      {
        "status": "affected",
        "version": "23.2.0",
        "versionType": "custom",
        "lessThanOrEqual": "23.2.10"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

7.4

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-5183