PT-2023-19707 · Open Xchange · Ox App Suite

·

CVE-2023-24605

·

Published

2023-05-29

·

Updated

2025-01-14

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OX App Suite versions prior to 7.10.6-rev37
Description The issue concerns the lack of enforcement of two-factor authentication (2FA) for all endpoints in OX App Suite. Specifically, endpoints such as reading from a drive, reading contact data, and renaming tokens are not properly secured with 2FA. This oversight could potentially allow unauthorized access to sensitive data.
Recommendations For versions prior to 7.10.6-rev37, update to version 7.10.6-rev37 or later to ensure 2FA is enforced for all endpoints. As a temporary workaround, consider restricting access to sensitive endpoints, such as those related to drive access, contact data, and token management, until the update can be applied.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-24605

Affected Products

Ox App Suite