#VU98005 Improper Authorization in RAID Web Console 3 - CVE-2023-4345


Vulnerability identifier: #VU98005

Vulnerability risk: Medium

CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-4345

CWE-ID: CWE-285

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
RAID Web Console 3
Universal components / Libraries / Software for developers

Vendor: Intel

Description

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to usage of client-side controls to limit access to sensitive functionality. A remote user can bypass implemented security restriction and gain access to sensitive information.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

RAID Web Console 3: All versions


External links
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00926.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability