CVE Feed

    Dashboard / CVE / CVE-2023-46047

    CVE-2023-46047

    An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.

    Published:Mar 27, 2024
    Last Modified:Nov 4, 2025
    EPS:Mar 27, 2024
    EPSS Score:0.00036
    CVSS Score:7.3

    Affected Products

    Vendor
    Sane-project
    Product
    Sane Backends

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High