2023-08-09 16:00:36 +00:00
{
"id" : "CVE-2023-3953" ,
"sourceIdentifier" : "cybersecurity@se.com" ,
"published" : "2023-08-09T15:15:09.623" ,
2023-08-15 16:00:43 +00:00
"lastModified" : "2023-08-15T15:40:42.007" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-08-09 16:00:36 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "\nA CWE-119: Improper Restriction of Operations within the Bounds of a Memory\nBuffer vulnerability exists that could cause memory corruption when an authenticated user\nopens a tampered log file from GP-Pro EX."
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Existe una vulnerabilidad CWE-119: Restricci\u00f3n inadecuada de operaciones dentro de los l\u00edmites de un b\u00fafer de memoria que podr\u00eda provocar da\u00f1os en la memoria cuando un usuario autenticado abre un archivo de registro manipulado desde GP-Pro EX."
2023-08-09 16:00:36 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-08-15 16:00:43 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.4
} ,
2023-08-09 16:00:36 +00:00
{
"source" : "cybersecurity@se.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.4
}
]
} ,
"weaknesses" : [
{
2023-08-15 16:00:43 +00:00
"source" : "nvd@nist.gov" ,
2023-08-09 16:00:36 +00:00
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-119"
}
]
2023-08-15 16:00:43 +00:00
} ,
{
"source" : "cybersecurity@se.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-119"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:schneider-electric:pro-face_gp-pro_ex:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.09.500" ,
"matchCriteriaId" : "CED20D73-6B2A-42AE-AFC8-C28284E88E5E"
}
]
}
]
2023-08-09 16:00:36 +00:00
}
] ,
"references" : [
{
"url" : "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-220-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-220-01.pdf" ,
2023-08-15 16:00:43 +00:00
"source" : "cybersecurity@se.com" ,
"tags" : [
"Vendor Advisory"
]
2023-08-09 16:00:36 +00:00
}
]
}