Access Control Flaw in Stormshield Endpoint Security Affects User Data Exposure
CVE-2023-23561

5.5MEDIUM

Key Information:

Vendor
CVE Published:
30 May 2023

What is CVE-2023-23561?

Stormshield Endpoint Security versions 2.3.0 to 2.3.2 are affected by an incorrect access control vulnerability. This issue allows authenticated users to gain unauthorized access to sensitive information, potentially compromising the confidentiality of user data and security protocols. Users should review their configurations and implement necessary security measures to mitigate the risks associated with this vulnerability. For further details, refer to the official advisories from Stormshield.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.