Description
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29677 | It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7152-d7f5b-1.html |
|
History
Thu, 09 Jan 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-01-08T18:01:59.090Z
Reserved: 2023-02-15T00:00:00.000Z
Link: CVE-2023-25780
Updated: 2024-08-02T11:32:11.998Z
Status : Modified
Published: 2023-06-02T11:15:10.157
Modified: 2024-11-21T07:50:11.357
Link: CVE-2023-25780
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD