IM
IronMonkey Threat Research

CVE-2023-5516 MEDIUM

Published: 2023-11-01 | Last Modified: 2024-11-21 | Status: Modified

Description

Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details. The website unintentionally reveals sensitive information including technical details like version Info, endpoints, backend server, Internal IP. etc., which can potentially expose additional attack surface containing other interesting vulnerabilities.

Additional Descriptions (1)

Las solicitudes de aplicaciones web mal construidas y los componentes URI con caracteres especiales desencadenan errores y excepciones no controlados, revelando información sobre la tecnología subyacente y otros detalles de información confidencial. El sitio web revela involuntariamente información confidencial, incluidos detalles técnicos como información de la versión, endpoints, servidor backend e IP interna. etc., lo que potencialmente puede exponer una superficie de ataque adicional que contiene otras vulnerabilidades interesantes.

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-200
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
hitachienergy esoms * <built-in method update of dict object at 0x72a9b0a6d740> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hitachienergy:esoms:*:*:*:*:*:*:*:*
Notification
Message here