PT-2024-14844 · Arc · Arc

Diego Giubertoni

·

Published

2024-05-15

·

Updated

2024-05-28

·

CVE-2023-5935

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arc (affected versions not specified)
Description The local web interface provided during the configuration of Arc lacks authentication, making it vulnerable to abuse by local attackers or malware. This could allow a malicious local user or process to extract sensitive information, change Arc's configuration, or potentially lead to arbitrary code execution if a malicious update package is installed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-5935

Affected Products

Arc