Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-41264

Опубликовано: 28 нояб. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and restSettings.AuthorizedSecret fields (for the POST /api/Deployment/ExportConfiguration and POST /api/Deployment endpoints).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:netwrix:usercube:*:*:*:*:*:*:*:*
Версия до 6.0.215 (исключая)

EPSS

Процентиль: 11%
0.00037
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 9.8
github
около 2 лет назад

Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and restSettings.AuthorizedSecret fields (for the POST /api/Deployment/ExportConfiguration and POST /api/Deployment endpoints).

EPSS

Процентиль: 11%
0.00037
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-287