← back
CVE-2023-28023

HCL BigFix WebUI Software Distribution is affected by a cross site server request forgery vulnerability

CVSS 4.9 MEDIUMEPSS 0.1%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.9EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
18 Jul 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A cross site request forgery vulnerability in the BigFix WebUI Software Distribution interface site version 44 and before allows an NMO attacker to access files on server side systems (server machine and all the ones in its network). 
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →