VulnerabilityModified
CVE-2023-23903
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format.
MEDIUM 6.9EPSS 0.60%
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console intervention.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1286
- Affected
- nozominetworks/cmc · nozominetworks/guardian
- Source
- prodsec@nozominetworks.com
References
- https://security.nozominetworks.com/NN-2023:7-01Vendor Advisory
- https://security.nozominetworks.com/NN-2023:7-01Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.