CVE-2023-24015: Partial DoS on Reports section due to null report name in Guardian/CMC before 22.6.2
A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a report to be saved with its name set as null.
The reports section will be partially unavailable for all later attempts to use it, with the report list seemingly stuck on loading.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24015?
The severity of CVE-2023-24015 is medium with a CVSS score of 4.3.
How can a malicious authenticated user exploit CVE-2023-24015?
A malicious authenticated user can exploit CVE-2023-24015 by forcing a report to be saved with its name set as null, causing a partial denial-of-service (DoS) in the Reports section.
Which software versions are affected by CVE-2023-24015?
The Nozominetworks Cmc and Nozominetworks Guardian software versions up to and excluding 22.6.2 are affected by CVE-2023-24015.
How does CVE-2023-24015 impact the Reports section?
CVE-2023-24015 impacts the Reports section by making it partially unavailable for all subsequent attempts to use, with the report list appearing to be stuck on loading.
Where can I find more information about CVE-2023-24015?
More information about CVE-2023-24015 can be found at the following reference link: [CVE-2023-24015 Reference](https://security.nozominetworks.com/NN-2023:6-01)