CVE-2023-28093: High severity Pega Synchronization Engine vulnerability
A user with a compromised configuration can start an unsigned binary as a service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28093?
CVE-2023-28093 is a vulnerability that allows a user with a compromised configuration to start an unsigned binary as a service.
What software is affected by CVE-2023-28093?
The Pega Synchronization Engine versions 3.1.1 to 3.1.30 are affected by CVE-2023-28093.
How can the vulnerability CVE-2023-28093 be exploited?
An attacker with a compromised configuration can exploit CVE-2023-28093 by starting an unsigned binary as a service.
What is the severity of CVE-2023-28093?
The severity of CVE-2023-28093 is high with a CVSS score of 6.5.
Where can I find more information about CVE-2023-28093?
You can find more information about CVE-2023-28093 in the following link: [support.pega.com/support-doc/pega-security-advisory-b23-robotics-and-workforce-intelligence-local-privilege](https://support.pega.com/support-doc/pega-security-advisory-b23-robotics-and-workforce-intelligence-local-privilege)