CVE-2023-25069

TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:trendmicro:txone_stellarone:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

07 Nov 2023, 04:08

Type Values Removed Values Added
Summary TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability. TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker could perform actions they are not authorized to. Please note: an attacker must first obtain a low-privileged authenticated user's profile on the target system in order to exploit this vulnerability.

24 Mar 2023, 20:47

Type Values Removed Values Added
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-23-231/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-23-231/ - Third Party Advisory, VDB Entry
References (MISC) https://success.trendmicro.com/solution/000292486 - (MISC) https://success.trendmicro.com/solution/000292486 - Vendor Advisory
First Time Trendmicro
Linux
Trendmicro txone Stellarone
Linux linux Kernel
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:txone_stellarone:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

22 Mar 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-22 06:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-25069

Mitre link : CVE-2023-25069

CVE.ORG link : CVE-2023-25069


JSON object : View

Products Affected

linux

  • linux_kernel

trendmicro

  • txone_stellarone