PT-2023-23524 · Suprema · Suprema Biostar 2
Published
2023-05-22
·
Updated
2023-06-01
·
CVE-2023-31923
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Suprema BioStar 2 versions prior to 2.9.1
Description
A vulnerability in the web application of Suprema BioStar 2 allows an authenticated attacker with
User Operator privileges to create a highly privileged user account. This issue is caused by missing server-side validation, which can be exploited to gain full administrator privileges on the system.Recommendations
For Suprema BioStar 2 versions prior to 2.9.1, update to version 2.9.1 or later to resolve the issue. As a temporary workaround, consider restricting the creation of new user accounts to prevent potential exploitation until the update is applied.
Exploit
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suprema Biostar 2