CVE Vulnerabilities

CVE-2023-7016

Improper Privilege Management

Published: Feb 27, 2024 | Modified: Mar 04, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Safenet_authentication_client Thalesgroup * 10.8 (excluding)
Safenet_authentication_client Thalesgroup 10.8 (including) 10.8 (including)
Safenet_authentication_client Thalesgroup 10.8-r1 (including) 10.8-r1 (including)
Safenet_authentication_client Thalesgroup 10.8-r5 (including) 10.8-r5 (including)
Safenet_authentication_client Thalesgroup 10.8-r6 (including) 10.8-r6 (including)
Safenet_authentication_client Thalesgroup 10.8-r8 (including) 10.8-r8 (including)
Safenet_authentication_client Thalesgroup 10.8-r9 (including) 10.8-r9 (including)

Potential Mitigations

References