2023-06-22 22:00:29 +00:00
{
"id" : "CVE-2023-2991" ,
"sourceIdentifier" : "cve@rapid7.con" ,
"published" : "2023-06-22T20:15:09.580" ,
2023-06-23 14:00:30 +00:00
"lastModified" : "2023-06-23T13:03:39.067" ,
"vulnStatus" : "Awaiting Analysis" ,
2023-06-22 22:00:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a \"trial extension request\" message\n"
}
] ,
"metrics" : { } ,
"weaknesses" : [
{
"source" : "cve@rapid7.con" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-200"
}
]
}
] ,
"references" : [
{
"url" : "https://kb.globalscape.com/Knowledgebase/11589/Is-EFT-susceptible-to-the-Remotely-obtain-HDD-serial-number-vulnerability" ,
"source" : "cve@rapid7.con"
} ,
{
"url" : "https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/" ,
"source" : "cve@rapid7.con"
}
]
}