CVE Vulnerabilities

CVE-2023-44320

Direct Request ('Forced Browsing')

Published: Nov 14, 2023 | Modified: Feb 13, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Affected devices do not properly validate the authentication when performing certain modifications in the web interface allowing an authenticated attacker to influence the user interface configured by an administrator.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
6gk5205-3bb00-2ab2_firmware Siemens * 4.5 (excluding)

Potential Mitigations

References