V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-33730
CVE
CriticalConfirmedExploit available

Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remo…

CVSS
9.8
Critical
EPSS
0.01
p63
Published
2023-01-01
Updated
2023-01-01
Description

Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.

Tags · CWE
Pre-auth
CWE-319
CAPEC-65
CAPEC-102
CAPEC-117
CAPEC-383
CAPEC-477
Affected products
Escan_management_console
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.012 · p63
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-65 · CWE-319
└ via CAPEC-383 · CWE-319
Known exploits — Сканер-ВС
CVE-2023-33730
github-poc · https://github.com/sahiloj/CVE-2023-33730
Enterprise
Affected products
ProductVendorStatus
escan_management_console*Tracked
Source databases
CVE