CVE-2023-24477

CVSS 3.1 Score 7.0 of 10 (high)

Details

Published Aug 9, 2023
Updated: May 28, 2024
CWE ID 384

Summary

CVE-2023-24477 is a vulnerability that affects Guardian/CMC versions before 22.6.2 when used with the Chrome web browser. In certain conditions, the user session is not completely invalidated upon logout, potentially allowing an authenticated local attacker to gain access to the original user's session. The vulnerability has a high severity rating with a base score of 7.0 and impacts both confidentiality and integrity. The exploitability score is 1.0, indicating that it is highly exploitable. To remediate this vulnerability, organizations should update their Guardian/CMC software to version 22.6.2 or later to ensure complete session invalidation upon logout and mitigate the risk of unauthorized access to user sessions.

Leverage our Vulnerability Intelligence module to secure your systems now - get detailed insights on CVE-2024-37364. Book your demo today.

Share

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-24477 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options