SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-26435

Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system user.

MEDIUM 5.0EPSS 0.78%

Does this matter?

Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.

Description

It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system user. This was limited to specific file-types, like images. We have improved existing content filters and validators to avoid including any local resources. No publicly available exploits are known.

CVSS 3.1
5.0 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
EPSS
0.78% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
open-xchange/open-xchange appsuite backend
Source
security@open-xchange.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.