#VU97992 Missing Authorization in RAID Web Console 3 - CVE-2023-4334

 

#VU97992 Missing Authorization in RAID Web Console 3 - CVE-2023-4334

Published: October 3, 2024


Vulnerability identifier: #VU97992
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-4334
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
RAID Web Console 3
Software vendor:
Intel

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to missing authorization when accessing private files. A remote attacker can request files directly from the server and gain access to sensitive information.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links