2024-07-14 02:06:08 +00:00

126 lines
3.9 KiB
JSON

{
"id": "CVE-2023-5777",
"sourceIdentifier": "ics-cert@hq.dhs.gov",
"published": "2023-11-06T20:15:08.033",
"lastModified": "2023-11-14T19:28:22.567",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "\n\n\nWeintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.\n\n\n\n"
},
{
"lang": "es",
"value": "Weintek EasyBuilder Pro contiene una vulnerabilidad que, incluso cuando la clave privada se elimina inmediatamente despu\u00e9s de finalizar la transmisi\u00f3n del informe de fallos, la clave privada queda expuesta al p\u00fablico, lo que podr\u00eda resultar en la obtenci\u00f3n de control remoto del servidor de informes de fallos."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
},
{
"source": "ics-cert@hq.dhs.gov",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
},
{
"source": "ics-cert@hq.dhs.gov",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:weintek:easybuilder_pro:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.07.02",
"matchCriteriaId": "B801ED0C-3420-487F-8661-3779C3101912"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:weintek:easybuilder_pro:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.08.01.190",
"versionEndExcluding": "6.08.01.614",
"matchCriteriaId": "8FC21AD1-D8A5-43D6-B9D6-EE993E1C3A6D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:weintek:easybuilder_pro:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.08.02",
"versionEndExcluding": "6.08.02.500",
"matchCriteriaId": "BE762A5D-0F39-4105-B335-DF2C3D6C989C"
}
]
}
]
}
],
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-306-05",
"source": "ics-cert@hq.dhs.gov",
"tags": [
"Third Party Advisory",
"US Government Resource"
]
}
]
}