CVE-2023-50441

Encrypted folders created by PRIMX ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission) or ZONECENTRAL for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which folders are opened.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:primx:zonecentral:*:*:*:*:*:windows:*:*
cpe:2.3:a:primx:zonecentral:*:*:*:*:*:windows:*:*

History

20 Dec 2023, 18:31

Type Values Removed Values Added
Summary
  • (es) Un atacante no autenticado puede modificar las carpetas cifradas creadas por PRIMX ZONECENTRAL para Windows antes de Q.2021.2 (envío de calificación ANSSI) o ZONECENTRAL para Windows antes de 2023.5 para incluir una referencia UNC que pueda activar el tráfico de red saliente desde las maquinas en las que se abren las carpetas.
CWE NVD-CWE-noinfo
First Time Primx
Primx zonecentral
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:primx:zonecentral:*:*:*:*:*:windows:*:*
References () https://www.primx.eu/en/bulletins/security-bulletin-23B3093A/ - () https://www.primx.eu/en/bulletins/security-bulletin-23B3093A/ - Vendor Advisory
References () https://www.primx.eu/fr/blog/ - () https://www.primx.eu/fr/blog/ - Product

13 Dec 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-13 20:15

Updated : 2023-12-20 18:31


NVD link : CVE-2023-50441

Mitre link : CVE-2023-50441

CVE.ORG link : CVE-2023-50441


JSON object : View

Products Affected

primx

  • zonecentral