CVE-2023-21311

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Oct 30, 2023
Updated: Nov 6, 2023
CWE ID 863

Summary

CVE-2023-21311 is a vulnerability affecting the settings functionality of a specific software. It allows secondary users to bypass permissions and control private DNS settings. This issue does not require any user interaction or additional execution privileges, making local information disclosure possible. The vulnerability could potentially be exploited without the primary user's knowledge.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share