CVE-2023-37524
Last modified
CVE-2023-37524 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Traveler For Microsoft Outlook | < 3.0.6 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-37524?
How severe is CVE-2023-37524?
How do I fix CVE-2023-37524?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-37519Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabil…6.1
- CVE-2023-3752A vulnerability was found in Creativeitem Academy LMS 5.15. …6.1
- CVE-2023-37520Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabil…6.1
- CVE-2023-37521HCL BigFix Bare OSD Metal Server WebUI version 311.19 or low…5.3
- CVE-2023-37522HCL BigFix Bare OSD Metal Server WebUI version 311.19 or low…9.8
- CVE-2023-37523Missing or insecure tags in the HCL BigFix Bare OSD Metal Se…9.8
- CVE-2023-37525A sensitive information disclosure in HCL BigFix Compliance …5.3
- CVE-2023-37526HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Reso…6.5
- CVE-2023-37527A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2023-37528A cross-site scripting (XSS) vulnerability in the Web Report…6.1
- CVE-2023-37529A cross-site scripting (XSS) vulnerability in the Web Report…5.4
- CVE-2023-3753A vulnerability classified as problematic has been found in …6.1
Are you affected by CVE-2023-37524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
