2023-11-28 23:00:22 +00:00
{
"id" : "CVE-2023-29066" ,
"sourceIdentifier" : "cybersecurity@bd.com" ,
"published" : "2023-11-28T21:15:08.173" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T07:56:29.510" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-11-28 23:00:22 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders."
2023-11-29 15:00:22 +00:00
} ,
{
"lang" : "es" ,
"value" : "El software FACSChorus no asigna correctamente privilegios de acceso a datos para las cuentas de usuario del sistema operativo. Una cuenta de sistema operativo no administrativa puede modificar la informaci\u00f3n almacenada en las carpetas de datos de la aplicaci\u00f3n local."
2023-11-28 23:00:22 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-12-05 17:00:22 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "cybersecurity@bd.com" ,
"type" : "Secondary" ,
2023-12-05 17:00:22 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" ,
"baseScore" : 3.2 ,
"baseSeverity" : "LOW" ,
2023-12-05 17:00:22 +00:00
"attackVector" : "PHYSICAL" ,
"attackComplexity" : "LOW" ,
2024-12-08 03:06:42 +00:00
"privilegesRequired" : "LOW" ,
2023-12-05 17:00:22 +00:00
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-12-05 17:00:22 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 0.7 ,
2023-12-05 17:00:22 +00:00
"impactScore" : 2.5
} ,
2023-11-28 23:00:22 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-11-28 23:00:22 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" ,
"baseScore" : 3.5 ,
"baseSeverity" : "LOW" ,
2023-11-28 23:00:22 +00:00
"attackVector" : "PHYSICAL" ,
"attackComplexity" : "LOW" ,
2024-12-08 03:06:42 +00:00
"privilegesRequired" : "NONE" ,
2023-11-28 23:00:22 +00:00
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2023-11-28 23:00:22 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 0.9 ,
2023-11-28 23:00:22 +00:00
"impactScore" : 2.5
}
]
} ,
"weaknesses" : [
2023-12-05 17:00:22 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "cybersecurity@bd.com" ,
"type" : "Secondary" ,
2023-12-05 17:00:22 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-266"
2023-12-05 17:00:22 +00:00
}
]
} ,
2023-11-28 23:00:22 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-11-28 23:00:22 +00:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-269"
2023-11-28 23:00:22 +00:00
}
]
}
] ,
2023-12-05 17:00:22 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:bd:facschorus:5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D5E0D4F-559B-414E-A627-0BA0937BD7F1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:bd:facschorus:5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "57F63FB2-2AE2-4B5F-8B49-4A0A4549CF3E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:hp_z2_tower_g9:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "54279DE4-A2A4-4AA6-A05F-931094446F16"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:bd:facschorus:3.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2785D17E-800C-4772-A131-5737E9446C01"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:bd:facschorus:3.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "30FD1DE4-982F-4D14-BB8A-478F8430BC63"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:hp:hp_z2_tower_g5:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E9BA28D-9C14-435A-9786-222BE58A9258"
}
]
}
]
}
] ,
2023-11-28 23:00:22 +00:00
"references" : [
{
"url" : "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software" ,
2023-12-05 17:00:22 +00:00
"source" : "cybersecurity@bd.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-11-28 23:00:22 +00:00
}
]
}