CVE-2023-38466
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2023-38466 is an identified vulnerability in the ims service that involves a missing permission check. This issue can lead to local information disclosure without the requirement for any additional execution privileges. An attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive information stored within the affected system. The exact impact of the information disclosed and the potential methods of exploitation vary depending on the specific configuration and implementation of the ims service. Organizations using this service are advised to apply the necessary patches or mitigations to address this vulnerability and prevent any unintended information exposure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android