CVE-2023-6263

An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:networkoptix:nxcloud:*:*:*:*:*:*:*:*

History

18 Dec 2023, 15:15

Type Values Removed Values Added
Summary (en) An issue was discovered in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server. (en) An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

04 Dec 2023, 14:40

Type Values Removed Values Added
First Time Networkoptix nxcloud
Networkoptix
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CPE cpe:2.3:a:networkoptix:nxcloud:*:*:*:*:*:*:*:*
CWE CWE-290
References () https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vulnerability+2023-09-21+-+Server+Spoofing - () https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vulnerability+2023-09-21+-+Server+Spoofing - Vendor Advisory

22 Nov 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-22 18:15

Updated : 2023-12-18 15:15


NVD link : CVE-2023-6263

Mitre link : CVE-2023-6263

CVE.ORG link : CVE-2023-6263


JSON object : View

Products Affected

networkoptix

  • nxcloud
CWE
CWE-290

Authentication Bypass by Spoofing