2023-09-05 18:00:28 +00:00
{
"id" : "CVE-2023-35124" ,
"sourceIdentifier" : "talos-cna@cisco.com" ,
"published" : "2023-09-05T17:15:09.237" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:07:59.337" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-09-05 18:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability."
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Existe una vulnerabilidad de divulgaci\u00f3n de informaci\u00f3n en la funcionalidad de gesti\u00f3n de configuraci\u00f3n del motor OAS de Open Automation Software OAS Platform v18.00.0072. Una serie de solicitudes de red especialmente manipuladas pueden dar lugar a la divulgaci\u00f3n de informaci\u00f3n sensible. Un atacante puede enviar una secuencia de solicitudes para desencadenar esta vulnerabilidad."
2023-09-05 18:00:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-09-08 18:00:28 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "talos-cna@cisco.com" ,
"type" : "Secondary" ,
2023-09-08 18:00:28 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"baseScore" : 3.1 ,
"baseSeverity" : "LOW" ,
2023-09-08 18:00:28 +00:00
"attackVector" : "NETWORK" ,
2024-12-08 03:06:42 +00:00
"attackComplexity" : "HIGH" ,
2023-09-08 18:00:28 +00:00
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-09-08 18:00:28 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 1.6 ,
2023-09-08 18:00:28 +00:00
"impactScore" : 1.4
} ,
2023-09-05 18:00:28 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-09-05 18:00:28 +00:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" ,
"baseScore" : 4.3 ,
"baseSeverity" : "MEDIUM" ,
2023-09-05 18:00:28 +00:00
"attackVector" : "NETWORK" ,
2024-12-08 03:06:42 +00:00
"attackComplexity" : "LOW" ,
2023-09-05 18:00:28 +00:00
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-09-05 18:00:28 +00:00
} ,
2024-12-08 03:06:42 +00:00
"exploitabilityScore" : 2.8 ,
2023-09-05 18:00:28 +00:00
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
{
"source" : "talos-cna@cisco.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-09-05 18:00:28 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-209"
}
]
}
] ,
2023-09-08 18:00:28 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:openautomationsoftware:oas_platform:18.00.0072:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "42650183-88E5-4F14-A46F-A6215E98B081"
}
]
}
]
}
] ,
2023-09-05 18:00:28 +00:00
"references" : [
{
"url" : "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1775" ,
2023-09-08 18:00:28 +00:00
"source" : "talos-cna@cisco.com" ,
"tags" : [
"Exploit" ,
"Technical Description" ,
"Third Party Advisory"
]
2023-09-05 20:00:40 +00:00
} ,
{
"url" : "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1775" ,
2023-09-08 18:00:28 +00:00
"source" : "talos-cna@cisco.com" ,
"tags" : [
"Exploit" ,
"Technical Description" ,
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://talosintelligence.com/vulnerability_reports/TALOS-2023-1775" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Technical Description" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1775" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Technical Description" ,
"Third Party Advisory"
]
2023-09-05 18:00:28 +00:00
}
]
}