CVE-2023-28016
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-28016 is a Host Header Injection vulnerability affecting the HCL BigFix OSD Bare Metal Server version 311.12 and below. An attacker can exploit this vulnerability by supplying invalid input, resulting in the OSD Bare Metal Server performing a redirect to a malicious domain under their control. This issue poses a significant risk, as it allows an attacker to potentially gain unauthorized access to sensitive information or install malware on the affected system. It is crucial that users of the affected version upgrade to a patched version as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- HCL Technologies Ltd.