CVE-2023-4816

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Sep 11, 2023
Updated: Sep 13, 2023
CWE ID 787

Summary

CVE-2023-4816 is a cybersecurity vulnerability affecting the Equipment Tag Out authentication feature, which can be exploited when Single Sign-On (SSO) with password validation is enabled in T214. An authenticated user can perform a holder action (Accept, Release, or Clear) for another user and input an arbitrary password in the confirmation dialog box. Surprisingly, the system will execute the selected holder action, disregarding the entered password, posing a significant risk to system security. This issue could potentially lead to unauthorized actions and data compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share