PT-2023-26709 · 42Gears · Suremdm

CVE-2023-3897

·

Publicado

2023-07-25

·

Atualizado

2024-08-13

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SureMDM On-premise versions 6.31 and below
Description The issue allows for username enumeration through bypassing CAPTCHA in the On-premise SureMDM Solution on Windows deployment. This enables an attacker to enumerate local user information via an error message.
Recommendations For versions 6.31 and below, update to a version above 6.31 to resolve the issue. As a temporary workaround, consider restricting access to the error message that reveals local user information to minimize the risk of exploitation.

Exploit

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3897

Produtos afetados

Suremdm