CVE-2024-23169

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 79

Summary

CVE-2024-23169 is a newly disclosed vulnerability affecting RSA NetWitness version 11.7.2.0. This issue permits Cross-Site Scripting (XSS) attacks through the Where textbox on the Reports screen during new rule creation in the web interface. Successful exploitation could result in unauthorized data access or theft of user credentials.Attackers could inject malicious scripts, potentially leading to session hijacking or data exfiltration.It is crucial for organizations using RSA NetWitness to update their software to a non-vulnerable version to mitigate the risk of XSS attacks.This vulnerability underscores the importance of secure coding practices and keeping software up-to-date to protect against potential cyber threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • NetWitness

Affected Vendors

  • NetWitness Corp