{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2023-0887", "ASSIGNER": "cna@vuldb.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The associated identifier of this vulnerability is VDB-221351." }, { "lang": "deu", "value": "Eine kritische Schwachstelle wurde in phjounin TFTPD64-SE 4.64 gefunden. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion der Datei tftpd64_svc.exe. Durch das Beeinflussen mit unbekannten Daten kann eine unquoted search path-Schwachstelle ausgenutzt werden. Umgesetzt werden muss der Angriff lokal. Die Komplexit\u00e4t eines Angriffs ist eher hoch. Die Ausnutzbarkeit gilt als schwierig." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-428 Unquoted Search Path", "cweId": "CWE-428" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "phjounin", "product": { "product_data": [ { "product_name": "TFTPD64-SE", "version": { "version_data": [ { "version_affected": "=", "version_value": "4.64" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://vuldb.com/?id.221351", "refsource": "MISC", "name": "https://vuldb.com/?id.221351" }, { "url": "https://vuldb.com/?ctiid.221351", "refsource": "MISC", "name": "https://vuldb.com/?ctiid.221351" } ] }, "credits": [ { "lang": "en", "value": "RedHatAugust (VulDB User)" } ], "impact": { "cvss": [ { "version": "3.1", "baseScore": 7, "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseSeverity": "HIGH" }, { "version": "3.0", "baseScore": 7, "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseSeverity": "HIGH" }, { "version": "2.0", "baseScore": 6, "vectorString": "AV:L/AC:H/Au:S/C:C/I:C/A:C" } ] } }