CVE-2023-5136
Last modified
CVE-2023-5136 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ni | Topografix Data Plugin | 2023 | — |
| Ni | Diadem | 2014 | — |
| Ni | Diadem | 2015 | — |
| Ni | Diadem | 2017 | — |
| Ni | Diadem | 2018 | — |
| Ni | Diadem | 2019 | — |
| Ni | Diadem | 2020 | — |
| Ni | Diadem | 2021 | — |
| Ni | Diadem | 2022 | Q2 |
| Ni | Diadem | 2023 | Q2 |
| Ni | Veristand | 2013 | Sp1 |
| Ni | Veristand | 2014 | — |
| Ni | Veristand | 2015 | — |
| Ni | Veristand | 2016 | — |
| Ni | Veristand | 2017 | — |
| Ni | Veristand | 2018 | — |
| Ni | Veristand | 2019 | — |
| Ni | Veristand | 2020 | — |
| Ni | Veristand | 2021 | — |
| Ni | Veristand | 2023 | Q1 |
| Ni | Flexlogger | 2018 | R1 |
| Ni | Flexlogger | 2019 | R1 |
| Ni | Flexlogger | 2020 | R1 |
| Ni | Flexlogger | 2021 | R1 |
| Ni | Flexlogger | 2022 | Q2 |
| Ni | Flexlogger | 2023 | Q1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-5136?
How severe is CVE-2023-5136?
How do I fix CVE-2023-5136?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-51354Cross-Site Request Forgery (CSRF) vulnerability in WebbaPlug…8.8
- CVE-2023-51355Missing Authorization vulnerability in MultiVendorX MultiVen…8.2
- CVE-2023-51356Improper Privilege Management vulnerability in Repute Infosy…8.8
- CVE-2023-51357Missing Authorization vulnerability in Conversios Conversios…5.3
- CVE-2023-51358Cross-Site Request Forgery (CSRF) vulnerability in Bright Pl…8.8
- CVE-2023-51359Missing Authorization vulnerability in WPDeveloper Essential…8.8
- CVE-2023-51360Missing Authorization vulnerability in WPDeveloper Essential…8.8
- CVE-2023-51361Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2023-51362Missing Authorization vulnerability in Premio My Sticky Elem…5.3
- CVE-2023-51363VR-S1000 firmware Ver. 2.37 and earlier allows a network-adj…6.5
- CVE-2023-51364A path traversal vulnerability has been reported to affect s…7.5
- CVE-2023-51365A path traversal vulnerability has been reported to affect s…7.5
Are you affected by CVE-2023-5136?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
