Description
A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null.

The reports section will be partially unavailable for all later attempts to use it, with the report list seemingly stuck on loading.
Published: 2023-08-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to v22.6.2 or later.


Vendor Workaround

Use internal firewall features to limit access to the web management interface.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-28079 A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null. The reports section will be partially unavailable for all later attempts to use it, with the report list seemingly stuck on loading.
History

Fri, 20 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 20 Sep 2024 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1286

Subscriptions

Nozominetworks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2024-09-20T12:07:25.358Z

Reserved: 2023-01-24T10:39:24.266Z

Link: CVE-2023-24015

cve-icon Vulnrichment

Updated: 2024-08-02T10:49:08.818Z

cve-icon NVD

Status : Modified

Published: 2023-08-09T10:15:09.890

Modified: 2024-11-21T07:47:15.730

Link: CVE-2023-24015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.