Vulnerability Description
XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Topdesk | Topdesk | 12.10.12 |
Related Weaknesses (CWE)
References
- https://char49.com/articles/topdesk-vulnerable-to-xml-signature-wrapping-attacksExploitTechnical DescriptionThird Party Advisory
- https://my.topdesk.com/tas/public/ssp/content/detail/knowledgeitem?unid=56a16ba1Permissions Required
- https://char49.com/articles/topdesk-vulnerable-to-xml-signature-wrapping-attacksExploitTechnical DescriptionThird Party Advisory
- https://my.topdesk.com/tas/public/ssp/content/detail/knowledgeitem?unid=56a16ba1Permissions Required
FAQ
What is CVE-2023-34923?
CVE-2023-34923 is a vulnerability with a CVSS score of 8.1 (HIGH). XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk use...
How severe is CVE-2023-34923?
CVE-2023-34923 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34923?
Check the references section above for vendor advisories and patch information. Affected products include: Topdesk Topdesk.