CVE-2023-38125
HIGHDescription
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of the web server. The issue results from the lack of appropriate Content Security Policy headers. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-20542.
Is your site exposed to CVE-2023-38125?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| softing | edgeaggregator |
| softing | edgeconnector |
| softing | secure_integration_server |
References
Frequently Asked Questions
What is CVE-2023-38125? +
How severe is CVE-2023-38125? +
What products are affected by CVE-2023-38125? +
How do I check if I'm vulnerable to CVE-2023-38125? +
Related Vulnerabilities
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to …
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability …
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability …
claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper …
Rob -- W / cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to …
Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in …