// For flags

CVE-2023-3425

CVE-2023-3425: Out-of-Bounds memory read

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.

Un problema de lectura fuera de los lĂ­mites en M-Files Server, el cual afecta a las versiones inferiores a 23.8.12892.6 y a las versiones de lanzamiento del servicio LTS inferiores a 23.2 LTS SR3. Esta vulnerabilidad permite a un usuario no autenticado leer una cantidad restringida de bytes de la memoria.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-06-27 CVE Reserved
  • 2023-08-25 CVE Published
  • 2024-08-28 CVE Updated
  • 2024-08-31 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-125: Out-of-bounds Read
CAPEC
  • CAPEC-540: Overread Buffers
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
M-files
Search vendor "M-files"
Classic Web
Search vendor "M-files" for product "Classic Web"
< 23.2
Search vendor "M-files" for product "Classic Web" and version " < 23.2"
lts
Affected
M-files
Search vendor "M-files"
Classic Web
Search vendor "M-files" for product "Classic Web"
< 23.6.12695.3
Search vendor "M-files" for product "Classic Web" and version " < 23.6.12695.3"
-
Affected
M-files
Search vendor "M-files"
Classic Web
Search vendor "M-files" for product "Classic Web"
23.2
Search vendor "M-files" for product "Classic Web" and version "23.2"
lts
Affected