← back
CVE-2023-41918

Missing Authentication for Critical Function in Kiloview P1/P2 devices

CVSS 10 CRITICALEPSS 0.6%CWE-306
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 10EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
02 Jul 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, access to privileged functions, or even the execution of arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Kiloview · P1/P2

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →