An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unblock traffic) from the mobile application. This vulnerability could create a "shutdown", blocking all ingress or egress traffic in the entire infrastructure where darktrace agents are deployed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 19 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-19T19:10:31.696Z

Reserved: 2023-04-07T00:00:00

Link: CVE-2023-29656

cve-icon Vulnrichment

Updated: 2024-08-02T14:14:39.893Z

cve-icon NVD

Status : Modified

Published: 2023-07-06T02:15:09.457

Modified: 2024-11-21T07:57:22.500

Link: CVE-2023-29656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.