← back
CVE-2023-5937mediumCWE-538

Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.2epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products
Nozomi Networks · Arc