PT-2025-18388 · Elastic · Endpoint Security+1

Published

2025-05-01

·

Updated

2025-05-02

·

CVE-2023-46669

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Elastic Agent and Elastic Security Endpoint (affected versions not specified)
Description Exposure of sensitive information to local unauthorized actors can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and there is no indication that it is known or has been exploited by malicious actors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-10466
CVE-2023-46669

Affected Products

Agent
Endpoint Security