PT-2023-24773 · M Files · M-Files Server

Published

2023-08-25

·

Updated

2024-08-28

·

CVE-2023-3425

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 23.8.12892.6 M-Files Server LTS Service Release Versions prior to 23.2 LTS SR3
Description The issue is an out-of-bounds read that allows an unauthenticated user to read a restricted amount of bytes from memory.
Recommendations For versions prior to 23.8.12892.6, update to version 23.8.12892.6 or later. For LTS Service Release Versions prior to 23.2 LTS SR3, update to 23.2 LTS SR3 or later.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2023-3425

Affected Products

M-Files Server