Vulnerability Description
An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Networkoptix | Nxcloud | < 23.1.0.40440 |
Related Weaknesses (CWE)
References
- https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vuVendor Advisory
- https://networkoptix.atlassian.net/wiki/spaces/CHS/blog/2023/09/22/3074195467/vuVendor Advisory
FAQ
What is CVE-2023-6263?
CVE-2023-6263 is a vulnerability with a CVSS score of 8.3 (HIGH). An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As ...
How severe is CVE-2023-6263?
CVE-2023-6263 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6263?
Check the references section above for vendor advisories and patch information. Affected products include: Networkoptix Nxcloud.