CVE Feed

    Dashboard / CVE / CVE-2023-4667

    CVE-2023-4667

    The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface.  The root cause of the vulnerability is inadequate input validation and output encoding in the web administration interface component of the firmware. This could lead to  unauthorized access and data leakage

    Published:Nov 28, 2023
    Last Modified:Nov 21, 2024
    EPS:Nov 28, 2023
    EPSS Score:0.00103
    CVSS Score:8.1

    Affected Products

    Vendor
    Idemia
    Product
    Morphowave Compact
    Vendor
    Idemia
    Product
    Morphowave Compact Firmware
    Vendor
    Idemia
    Product
    Morphowave Sp
    Vendor
    Idemia
    Product
    Morphowave Sp Firmware
    Vendor
    Idemia
    Product
    Morphowave Xp
    Vendor
    Idemia
    Product
    Sgima Lite \& Lite\+
    Vendor
    Idemia
    Product
    Sgima Lite \& Lite\+ Firmware
    Vendor
    Idemia
    Product
    Sigma Extreme
    Vendor
    Idemia
    Product
    Sigma Extreme Firmware
    Vendor
    Idemia
    Product
    Sigma Lite
    Vendor
    Idemia
    Product
    Sigma Lite\+
    Vendor
    Idemia
    Product
    Sigma Wide
    Vendor
    Idemia
    Product
    Sigma Wide Firmware
    Vendor
    Idemia
    Product
    Visionpass
    Vendor
    Idemia
    Product
    Visionpass Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High