CVE-2023-25914
Last modified
CVE-2023-25914 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Danfoss | Ak-Sm 800a Firmware | <= 3.3 |
References
- https://csirt.divd.nl/CVE-2023-25914Third Party Advisory
- https://csirt.divd.nl/DIVD-2023-00025Third Party Advisory
- https://csirt.divd.nl/CVE-2023-25914Third Party Advisory
- https://csirt.divd.nl/DIVD-2023-00025Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-25914?
How severe is CVE-2023-25914?
How do I fix CVE-2023-25914?
Are you affected by CVE-2023-25914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
