CVE-2023-38442

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Sep 4, 2023
Updated: Sep 8, 2023
CWE ID 862

Summary

CVE-2023-38442 is a vulnerability affecting the vowifiservice component. This issue involves a missing permission check, which could be exploited to disclose local information without requiring any additional execution privileges. The flaw resides within the access control mechanism, posing a risk to the confidentiality of sensitive data. Successful exploitation of this vulnerability does not grant attackers the ability to run arbitrary code, but rather allows them to gain unauthorized access to protected information. Organizations using this affected component are advised to install patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share