CVE-2023-23903: DoS via SAML configuration in Guardian/CMC before 22.6.2
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error.
The whole application in rendered unusable until a console intervention.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23903.
What is the severity of CVE-2023-23903?
The severity of CVE-2023-23903 is medium.
What is the affected software?
The affected software is Nozominetworks Cmc version up to exclusive 22.6.2 and Nozominetworks Guardian version up to exclusive 22.6.2.
How does CVE-2023-23903 affect the application?
An authenticated administrator can upload a SAML configuration file with the wrong format, rendering the whole application unusable until a console intervention.
How can CVE-2023-23903 be fixed?
To fix CVE-2023-23903, the application needs to implement proper file format checking for uploaded SAML configuration files.