CVE-2023-2809
Last modified
CVE-2023-2809 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution of MS SQL commands and escalate privileges on Windows systems because the credentials are stored in plaintext.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution of MS SQL commands and escalate privileges on Windows systems because the credentials are stored in plaintext.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sage | Sage 200 Spain | 2023.38.001 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-2809?
How severe is CVE-2023-2809?
How do I fix CVE-2023-2809?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-28084HPE OneView and HPE OneView Global Dashboard appliance dumps…5.5
- CVE-2023-28085An HPE OneView Global Dashboard (OVGD) appliance dump may ex…5.5
- CVE-2023-28086An HPE OneView appliance dump may expose proxy credential se…5.5
- CVE-2023-28087An HPE OneView appliance dump may expose OneView user accoun…5.5
- CVE-2023-28088An HPE OneView appliance dump may expose SAN switch administ…7.8
- CVE-2023-28089An HPE OneView appliance dump may expose FTP credentials for…7.1
- CVE-2023-28090An HPE OneView appliance dump may expose SNMPv3 read credent…5.5
- CVE-2023-28091HPE OneView virtual appliance "Migrate server hardware" opti…5.5
- CVE-2023-28092A potential security vulnerability has been identified in HP…6.8
- CVE-2023-28093A user with a compromised configuration can start an unsigne…6.5
- CVE-2023-28094Pega platform clients who are using versions 7.4 through 8.8…9.8
- CVE-2023-28095OpenSIPS is a Session Initiation Protocol (SIP) server imple…7.5
Are you affected by CVE-2023-2809?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
