Improper Authentication in North Grid Corporation products - CVE-2023-39415

 

Improper Authentication in North Grid Corporation products - CVE-2023-39415

Published: August 24, 2023


Vulnerability identifier: #VU79933
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39415
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can log in to the product's Control Panel and perform an unintended operation.


Affected software

Proself Enterprise Edition
Proself Standard Edition
Proself Gateway Edition
Proself Mail Sanitize Edition

How to mitigate CVE-2023-39415

Install updates from vendor's website.

Proself Enterprise Edition - update to 5.62
Proself Standard Edition - update to 5.62
Proself Gateway Edition - update to 1.65
Proself Mail Sanitize Edition - update to 1.08

External References

Related Security Bulletins