CVE Feed

    Dashboard / CVE / CVE-2023-43870

    CVE-2023-43870

    When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certificate and password they could then create their own certificates to emulate another site. Then by establishing a proxy service to emulate the site they could monitor traffic passed between the end user and the site allowing access to the data content.

    Published:Dec 19, 2023
    Last Modified:Nov 27, 2024
    EPS:Dec 19, 2023
    EPSS Score:0.00068
    CVSS Score:8.1

    Affected Products

    Vendor
    Paxton-access
    Product
    Net2

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High