CVE Vulnerabilities

CVE-2023-5993

Improper Privilege Management

Published: Feb 27, 2024 | Modified: Mar 04, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Safenet_authentication_clientThalesgroup*10.8 (excluding)
Safenet_authentication_clientThalesgroup10.8 (including)10.8 (including)
Safenet_authentication_clientThalesgroup10.8-r1 (including)10.8-r1 (including)
Safenet_authentication_clientThalesgroup10.8-r5 (including)10.8-r5 (including)
Safenet_authentication_clientThalesgroup10.8-r6 (including)10.8-r6 (including)
Safenet_authentication_clientThalesgroup10.8-r8 (including)10.8-r8 (including)
Safenet_authentication_clientThalesgroup10.8-r9 (including)10.8-r9 (including)

Potential Mitigations

References