mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-07 13:36:56 +00:00
135 lines
4.7 KiB
JSON
135 lines
4.7 KiB
JSON
{
|
|
"id": "CVE-2023-50439",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2023-12-13T21:15:09.563",
|
|
"lastModified": "2024-11-21T08:36:59.663",
|
|
"vulnStatus": "Modified",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission), ZED! for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before 2023.5, or ZEDMAIL for Windows before 2023.5 disclose the original path in which the containers were created, which allows an unauthenticated attacker to obtain some information regarding the context of use (project name, etc.)."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Contenedores ZED producidos por PRIMX ZED! para Windows anterior a Q.2020.3 (env\u00edo de calificaci\u00f3n ANSSI), ZED! para Windows antes de Q.2021.2 (env\u00edo de calificaci\u00f3n ANSSI), ZONECENTRAL para Windows antes de Q.2021.2 (env\u00edo de calificaci\u00f3n ANSSI), ZONECENTRAL para Windows antes de 2023.5 o ZEDMAIL para Windows antes de 2023.5 divulgan la ruta original en la que se crearon los contenedores, lo que permite un atacante no autenticado para obtener informaci\u00f3n sobre el contexto de uso (nombre del proyecto, etc.)."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
|
|
"baseScore": 5.3,
|
|
"baseSeverity": "MEDIUM",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 1.4
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "NVD-CWE-noinfo"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:primx:zed\\!:*:*:*:*:enterprise:windows:*:*",
|
|
"versionEndExcluding": "q.2020.3",
|
|
"matchCriteriaId": "7C67598A-6CE7-4802-BB1F-65D40CF38DAC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:primx:zed\\!:*:*:*:*:enterprise:windows:*:*",
|
|
"versionStartIncluding": "2023.0",
|
|
"versionEndExcluding": "2023.5",
|
|
"matchCriteriaId": "1B21D96F-47D7-4DE6-80AD-68986FF75C77"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:primx:zed\\!:*:*:*:*:enterprise:windows:*:*",
|
|
"versionStartIncluding": "q.2021.0",
|
|
"versionEndExcluding": "q.2021.2",
|
|
"matchCriteriaId": "747C7A04-7E6E-4A2C-BCFC-01EC16ABE951"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:primx:zedmail:*:*:*:*:*:windows:*:*",
|
|
"versionEndExcluding": "2023.5",
|
|
"matchCriteriaId": "01B1BDF0-697E-4EA2-8E26-5B786E03FCF1"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:primx:zonecentral:*:*:*:*:*:windows:*:*",
|
|
"versionEndExcluding": "q.2021.2",
|
|
"matchCriteriaId": "60E1C4D1-FD43-44D1-90E3-0A3936D947A2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:primx:zonecentral:*:*:*:*:*:windows:*:*",
|
|
"versionStartIncluding": "2023.0",
|
|
"versionEndExcluding": "2023.5",
|
|
"matchCriteriaId": "5FA52575-445D-48F8-B1D9-F3981DDBD5D3"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://www.primx.eu/en/bulletins/security-bulletin-23B30930/",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://www.primx.eu/fr/blog/",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Product"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://www.primx.eu/en/bulletins/security-bulletin-23B30930/",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "https://www.primx.eu/fr/blog/",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Product"
|
|
]
|
|
}
|
|
]
|
|
} |