PT-2023-29765 · Wipotec Gmbh · Comscale

Daniel Hoffmann

·

Published

2023-10-18

·

Updated

2025-01-09

·

CVE-2023-45912

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WIPOTEC GmbH ComScale versions 4.3.29.21344 through 4.4.12.723
Description The issue allows unauthenticated attackers to read files from the underlying operating system and obtain directory listings due to a failure in validating user sessions.
Recommendations For versions 4.3.29.21344 and 4.4.12.723, consider restricting access to sensitive files and directories on the underlying operating system until a patch is available. As a temporary workaround, restrict access to the ComScale system to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-45912

Affected Products

Comscale