cve/2023/CVE-2023-2991.md

18 lines
892 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-2991](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2991)
![](https://img.shields.io/static/v1?label=Product&message=Globalscape%20EFT&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%208.0.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-200%20Exposure%20of%20Sensitive%20Information%20to%20an%20Unauthorized%20Actor&color=brighgreen)
### Description
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message
### POC
#### Reference
- https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/
#### Github
- https://github.com/rbowes-r7/gestalt