Vulnerability Description
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc. despite Virtual Host Routing being used to block this access. Remote attackers can interact with private pages on the web server, enabling them to perform privileged actions such as logging into the console and changing console settings if they have valid credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Faronics | Insight | 10.0.19045 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://research.nccgroup.com/2023/05/30/technical-advisory-multiple-vulnerabiliExploitMitigationRelease Notes
- https://research.nccgroup.com/?research=Technical%20advisoriesThird Party Advisory
- https://research.nccgroup.com/2023/05/30/technical-advisory-multiple-vulnerabiliExploitMitigationRelease Notes
- https://research.nccgroup.com/?research=Technical%20advisoriesThird Party Advisory
FAQ
What is CVE-2023-28346?
CVE-2023-28346 is a vulnerability with a CVSS score of 7.3 (HIGH). An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API endpoints exposed at /login, /consoleSettings, /console, etc...
How severe is CVE-2023-28346?
CVE-2023-28346 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28346?
Check the references section above for vendor advisories and patch information. Affected products include: Faronics Insight, Microsoft Windows.