CVE-2023-27195
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-27195 is a vulnerability affecting Trimble TM4Web version 22.2.0. An unauthenticated attacker can exploit this issue by sending a PUT request to the /inc/tm_ajax.msw endpoint with a specific function call. The function, UserfromUUID, can be used to retrieve the last registration access code, which an attacker can then use to register a new valid account. In the case where an Administrator account was created using the obtained access code, attackers are granted full privileges to the affected system, enabling them to register new Administrator accounts as well.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.