← back
CVE-2023-22948

CVE-2023-22948

CVSS 4.9 MEDIUMEPSS 0.4%CWE-311
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.9EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Apr 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read the SSH private key. With this, an attacker is granted password-less SSH access to all machines in the TigerGraph cluster.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →