← voltar
CVE-2023-5183criticalCWE-502

Authenticated RCE due to unsafe JSON deserialization

28Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 9.9epss 1.6%
probabilidade de exploração
1.6%top 26% das CVEs
exploração observada
nãonenhuma fonte reporta
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.  
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
Illumio · Core PCE