SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-24015

A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null.

MEDIUM 5.3EPSS 0.55%

Does this matter?

Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.

Description

A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null. The reports section will be partially unavailable for all later attempts to use it, with the report list seemingly stuck on loading.

CVSS 4.0
5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.55% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-1286
Affected
nozominetworks/cmc · nozominetworks/guardian
Source
prodsec@nozominetworks.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.