PT-2023-23332 · Unknown · Cassia Access Controller

Published

2023-05-11

·

Updated

2024-01-29

·

CVE-2023-31445

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cassia Access controller versions prior to 2.1.1.2203171453
Description The issue allows read-only users to enumerate all other users and discover sensitive information, including e-mail addresses, phone numbers, and privileges of all other users.
Recommendations For versions prior to 2.1.1.2203171453, update to version 2.1.1.2203171453 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive user information until the update is applied.

Exploit

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2023-31445

Affected Products

Cassia Access Controller