PT-2023-27010 · Unknown · Clusterpro X+3

David Levard

·

Published

2023-11-17

·

Updated

2023-11-24

·

CVE-2023-39544

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CLUSTERPRO X versions 5.1 and earlier EXPRESSCLUSTER X versions 5.1 and earlier CLUSTERPRO X SingleServerSafe versions 5.1 and earlier EXPRESSCLUSTER X SingleServerSafe versions 5.1 and earlier
Description The issue allows an attacker to log in to the product and may execute an arbitrary command.
Recommendations For CLUSTERPRO X versions 5.1 and earlier, update to a version later than 5.1 to resolve the issue. For EXPRESSCLUSTER X versions 5.1 and earlier, update to a version later than 5.1 to resolve the issue. For CLUSTERPRO X SingleServerSafe versions 5.1 and earlier, update to a version later than 5.1 to resolve the issue. For EXPRESSCLUSTER X SingleServerSafe versions 5.1 and earlier, update to a version later than 5.1 to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-39544

Affected Products

Clusterpro X
Clusterpro X Singleserversafe
Expresscluster X
Expresscluster X Singleserversafe