Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-24523

Опубликовано: 14 фев. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges.  The OS command can read or modify any user or system data and can make the system unavailable.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:host_agent:7.21:*:*:*:*:*:*:*
cpe:2.3:a:sap:host_agent:7.22:*:*:*:*:*:*:*

EPSS

Процентиль: 9%
0.00036
Низкий

8.8 High

CVSS3

Дефекты

CWE-668
CWE-668

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.

EPSS

Процентиль: 9%
0.00036
Низкий

8.8 High

CVSS3

Дефекты

CWE-668
CWE-668