CVE-2023-6151
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 28, 2023
Updated: Dec 5, 2023
CWE ID 648
Summary
CVE-2023-6151 is an Improper Privilege Management vulnerability affecting the e-municipality module before version 105 used by ESKOM Computer. This issue grants Collect Data permissions to users, bypassing necessary access controls. This vulnerability may lead to unauthorized data access, potentially posing a significant risk to the confidentiality and integrity of affected systems. Organizations using the e-municipality module are advised to apply the necessary security updates as soon as possible to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Eskom