CVE-2023-0093
CVE-2023-0093
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an attacker would need to phish the user to enter an attacker controlled server URL during enrollment.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Okta · Advanced Server AccessWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →