CVE-2023-25069

TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trendmicro:txone_stellarone:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:49

Type Values Removed Values Added
References () https://success.trendmicro.com/solution/000292486 - Vendor Advisory () https://success.trendmicro.com/solution/000292486 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-23-231/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-23-231/ - Third Party Advisory, VDB Entry

07 Nov 2023, 04:08

Type Values Removed Values Added
Summary TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability. TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability.

Information

Published : 2023-03-22 06:15

Updated : 2024-11-21 07:49


NVD link : CVE-2023-25069

Mitre link : CVE-2023-25069

CVE.ORG link : CVE-2023-25069


JSON object : View

Products Affected

trendmicro

  • txone_stellarone

linux

  • linux_kernel