CVE-2023-6070
Last modified
CVE-2023-6070 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data . EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trellix | Enterprise Security Manager | < 11.6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-6070?
How severe is CVE-2023-6070?
How do I fix CVE-2023-6070?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-6064The PayHere Payment Gateway WordPress plugin before 2.2.12 a…7.5
- CVE-2023-6065The Quttera Web Malware Scanner WordPress plugin before 3.4.…5.3
- CVE-2023-6066The WP Custom Widget area WordPress plugin through 1.2.5 doe…4.3
- CVE-2023-6067The WP User Profile Avatar WordPress plugin through 1.0.1 do…5.4
- CVE-2023-6068On affected 7130 Series FPGA platforms running MOS and recen…3.1
- CVE-2023-6069Improper Link Resolution Before File Access in GitHub reposi…8.8
- CVE-2023-6071 An Improper Neutralization of Special Elements used in a co…7.2
- CVE-2023-6072 A cross-site scripting vulnerability in Trellix Central Man…5.4
- CVE-2023-6073Attacker can perform a Denial of Service attack to crash the…6.3
- CVE-2023-6074A vulnerability was found in PHPGurukul Restaurant Table Boo…9.8
- CVE-2023-6075A vulnerability classified as problematic has been found in …6.1
- CVE-2023-6076A vulnerability classified as problematic was found in PHPGu…7.5
Are you affected by CVE-2023-6070?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
