Description
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
upgrade to versions 5.12.2, 5.11.2 or 5.13
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53898 | One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges. |
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories |
|
History
Mon, 23 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-09-23T20:08:03.356Z
Reserved: 2023-07-30T10:40:54.605Z
Link: CVE-2023-4003
Updated: 2024-08-02T07:17:10.434Z
Status : Modified
Published: 2023-09-27T15:19:39.847
Modified: 2024-11-21T08:34:12.223
Link: CVE-2023-4003
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD