CVE-2023-45598
MEDIUMDescription
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ailux | imx6 |
References
Frequently Asked Questions
What is CVE-2023-45598? +
How severe is CVE-2023-45598? +
What products are affected by CVE-2023-45598? +
How do I check if I'm vulnerable to CVE-2023-45598? +
Related Vulnerabilities
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged …
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information.
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly …
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to …
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an …
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the …