CVE-2023-40685

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 29, 2023
Updated: Nov 8, 2023
CWE ID 269

Summary

CVE-2023-40685 is a local privilege escalation vulnerability affecting IBM i 7.2, 7.3, 7.4, and 7.5 Navigator's Management Central component. A malicious user with command line access to the operating system can exploit this flaw to elevate their privileges and gain root access. IBM's X-Force has identified this issue with ID 264116. This vulnerability poses a significant risk as it allows an attacker to bypass access controls and take complete control of the affected system. IBM urges users to apply the available patches or workarounds to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM OS/400

Affected Vendors

  • IBM Corporation