#VU97311 Insufficient Session Expiration in RAID Web Console 3 - CVE-2023-4323
Published: September 16, 2024
Vulnerability identifier: #VU97311
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-4323
CWE-ID: CWE-613
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
RAID Web Console 3
RAID Web Console 3
Software vendor:
Intel
Intel
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient session expiration issue. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.