Lucene search

K
vulnrichmentCertccVULNRICHMENT:CVE-2023-7007
HistoryMar 15, 2024 - 5:08 p.m.

CVE-2023-7007 CVE-2023-7007

2024-03-1517:08:58
certcc
github.com
1
sciener server
gatewayg2
impersonation attack
unlockkey field

AI Score

6.9

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Sciener server does not validate connection requests from the GatewayG2, allowing an impersonation attack that provides the attacker the unlockKey field.

CNA Affected

[
  {
    "vendor": "Sciener",
    "product": "Gateway G2",
    "versions": [
      {
        "status": "affected",
        "version": "6.0.0",
        "versionType": "custom",
        "lessThanOrEqual": "6.0.0"
      }
    ]
  }
]

AI Score

6.9

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-7007