2023-08-23 23:55:33 +00:00
{
"id" : "CVE-2023-38422" ,
"sourceIdentifier" : "ics-cert@hq.dhs.gov" ,
"published" : "2023-08-23T22:15:08.693" ,
2023-09-05 20:00:40 +00:00
"lastModified" : "2023-09-05T19:41:08.010" ,
"vulnStatus" : "Analyzed" ,
2023-08-23 23:55:33 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the management web server. This could allow an attacker to download and export sensitive data.\n"
2023-09-05 20:00:40 +00:00
} ,
{
"lang" : "es" ,
"value" : "La versiones de firmware de Walchem Intuition 9 anteriores a la v4.21 carecen de autenticaci\u00f3n para algunas de las rutas API del servidor web de gesti\u00f3n. Esto podr\u00eda permitir a un atacante descargar y exportar datos sensibles. "
2023-08-23 23:55:33 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-09-05 20:00:40 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
} ,
2023-08-23 23:55:33 +00:00
{
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-306"
}
]
}
] ,
2023-09-05 20:00:40 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:walchem:intuition_9:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3E7C1440-FDB8-49F9-B2A1-981AEE899035"
2023-09-05 20:00:40 +00:00
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
2024-05-19 02:03:31 +00:00
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:walchem:intuition_9_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.21" ,
"matchCriteriaId" : "4646AA8D-0D63-4026-AB76-29D13BFEAE8B"
2023-09-05 20:00:40 +00:00
}
]
}
]
}
] ,
2023-08-23 23:55:33 +00:00
"references" : [
{
"url" : "https://www.cisa.gov/news-events/ics-advisories/icsa-23-229-04" ,
2023-09-05 20:00:40 +00:00
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
2023-08-23 23:55:33 +00:00
}
]
}