Improper Authentication in Remote Management System (RMS) - CVE-2023-32347
Published: May 15, 2023
Vulnerability identifier: #VU76151
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32347
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker can obtain the serial number and MAC address of the device, bypass authentication process and gain unauthorized access to the application.
Affected software
Remote Management System (RMS)
How to mitigate CVE-2023-32347
Install updates from vendor's website.
Remote Management System (RMS) - update to 4.10.0