Fortra Globalscape Administration Server Information Disclosure

CVE-2023-2991
5.3MEDIUM

Key Information

Vendor
Fortra
Status
Globalscape EFT
Vendor
CVE Published:
22 June 2023

Summary

Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message

Affected Version(s)

Globalscape EFT = 8.0.0

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.