Vulnerability Description
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Bigfix Osd Bare Metal Server | <= 311.12 |
Related Weaknesses (CWE)
References
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105601Vendor Advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0105601Vendor Advisory
FAQ
What is CVE-2023-23343?
CVE-2023-23343 is a vulnerability with a CVSS score of 2.4 (LOW). A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on an...
How severe is CVE-2023-23343?
CVE-2023-23343 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23343?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltech Bigfix Osd Bare Metal Server.