SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-6253

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

MEDIUM 6.0EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

CVSS 3.1
6.0 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS
0.31% probability · 23th percentile
CISA KEV
Not listed
Weakness
CWE-922
Affected
fortra/digital guardian agent
Source
551230f0-3615-47bd-b7cc-93e92e730bbf

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.