← back
CVE-2023-27001

CVE-2023-27001

CVSS 8.8 HIGHEPSS 0.9%
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Feb 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →