Vulnerability Description
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachienergy | Modular Advanced Control For Hvdc | >= 7.10.0.0, <= 7.18.0.0 |
Related Weaknesses (CWE)
References
- https://publisher.hitachienergy.com/preview?DocumentId=8DBD000177&languageCode=eVendor Advisory
- https://publisher.hitachienergy.com/preview?DocumentId=8DBD000177&languageCode=eVendor Advisory
FAQ
What is CVE-2023-2622?
CVE-2023-2622 is a vulnerability with a CVSS score of 2.7 (LOW). Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read...
How severe is CVE-2023-2622?
CVE-2023-2622 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2622?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachienergy Modular Advanced Control For Hvdc.