Vulnerability Description
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool directory, and then sending a signal to the VNC service, which automatically transfers them to the connected VNC client's filesystem.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| M-Privacy | Mprivacy-Tools | < 2.0.406g |
| M-Privacy | Tightgatevnc | < 4.1.2-1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-ExecutiExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2023/Nov/13ExploitMailing ListThird Party Advisory
- https://sec-consult.com/en/vulnerability-lab/advisories/index.htmlThird Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-mThird Party Advisory
- https://www.m-privacy.de/en/tightgate-pro-safe-surfing/Product
- http://packetstormsecurity.com/files/175949/m-privacy-TightGate-Pro-Code-ExecutiExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2023/Nov/13ExploitMailing ListThird Party Advisory
- https://sec-consult.com/en/vulnerability-lab/advisories/index.htmlThird Party Advisory
- https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilities-in-mThird Party Advisory
- https://www.m-privacy.de/en/tightgate-pro-safe-surfing/Product
FAQ
What is CVE-2023-47251?
CVE-2023-47251 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to aut...
How severe is CVE-2023-47251?
CVE-2023-47251 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47251?
Check the references section above for vendor advisories and patch information. Affected products include: M-Privacy Mprivacy-Tools, M-Privacy Tightgatevnc.