14 Sep 2023
Vulnérabilité CVE-2023-4516 CVE Vulnerability
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change update source, potentially leading to remote
code execution when the attacker force an update containing malicious content. (CVSS:7.8) (Last Update:2023-09-14 09:15:09)
Vulnerability Details :
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS UpdateService that could allow a local attacker to change update source, potentially leading to remotecode execution when the attacker force an update containing malicious content.
Vulnerability category:Execute code
Exploit prediction scoring system (EPSS) score for CVE-2023-4516
We don't have an EPSS score for this CVE yet EPSS FAQ
CVSS scores for CVE-2023-4516
Base Score | Base Severity | CVSS Vector | Exploitability Score | Impact Score | Source |
---|---|---|---|---|---|
7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 1.8 | 5.9 | [email protected] |
CWE ids for CVE-2023-4516
- The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.Assigned by: [email protected] (Primary)