PT-2023-22115 · Xcc · Xcc

Published

2023-04-28

·

Updated

2023-05-10

·

CVE-2023-29057

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XCC (affected versions not specified)
Description The issue concerns a scenario where a valid XCC user's local account permissions take precedence over their active directory permissions under specific configurations, potentially leading to a privilege escalation. For this issue to be exploitable, LDAP must be configured for authentication and authorization, and logins must be set up as "Local First, then LDAP".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2023-29057

Affected Products

Xcc