CVE-2023-2989 Vulnerability Details
/
/
/
CVE-2023-2989 Metadata Quick Info
CVE Published: 22/06/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023
Source: rapid7 |
Vendor: Fortra |
Product: Globalscape EFT
Status : PUBLISHED
CVE-2023-2989 Description
Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-125
CWE Name: CWE-125 Out-of-bounds Read
Source: Fortra
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).