An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error.
The whole application in rendered unusable until a console intervention.
The whole application in rendered unusable until a console intervention.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-27986 | An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console intervention. |
Fixes
Solution
Upgrade to v22.6.2 or later.
Workaround
Use internal firewall features to limit access to the web management interface.
References
Link | Providers |
---|---|
https://security.nozominetworks.com/NN-2023:7-01 |
![]() ![]() |
History
Fri, 20 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 20 Sep 2024 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 |
Fri, 20 Sep 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-1286 |

Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2024-09-20T12:09:31.800Z
Reserved: 2023-01-24T10:39:24.300Z
Link: CVE-2023-23903

Updated: 2024-08-02T10:42:26.840Z

Status : Modified
Published: 2023-08-09T10:15:09.687
Modified: 2024-11-21T07:47:04.113
Link: CVE-2023-23903

No data.

No data.