The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request.
By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-52322 The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published:

Updated: 2025-06-17T20:59:13.701Z

Reserved: 2023-11-13T13:44:23.705Z

Link: CVE-2023-48253

cve-icon Vulnrichment

Updated: 2024-08-02T21:23:39.464Z

cve-icon NVD

Status : Modified

Published: 2024-01-10T13:15:45.803

Modified: 2024-11-21T08:31:19.600

Link: CVE-2023-48253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.