IM
IronMonkey Threat Research

CVE-2023-5514 MEDIUM

Published: 2023-11-01 | Last Modified: 2024-11-21 | Status: Modified

Description

The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

Additional Descriptions (1)

Se puede abusar de los mensajes de respuesta recibidos de la generación del informe eSOMS utilizando ciertas consultas de parámetros con la ruta completa del archivo para enumerar la estructura del sistema de archivos local.

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-209
[email protected] Primary
en CWE-209

Affected Products

Vendor Product Version Update Type
hitachienergy esoms * <built-in method update of dict object at 0x72a9b0db51c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hitachienergy:esoms:*:*:*:*:*:*:*:*
Notification
Message here