CVE-2023-28352: High severity faronics insight vulnerability
An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console even after Enhanced Security Mode has been enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28352?
CVE-2023-28352 is classified as a high severity vulnerability due to the potential for an attacker to remotely access and control sensitive Teacher Console functions.
How do I fix CVE-2023-28352?
To mitigate CVE-2023-28352, ensure that Faronics Insight is updated to a version that addresses this vulnerability.
What systems are affected by CVE-2023-28352?
CVE-2023-28352 specifically affects Faronics Insight version 10.0.19045 on Windows platforms.
What type of attack is possible with CVE-2023-28352?
CVE-2023-28352 allows an attacker to exploit the UDP broadcast discovery system to connect and attack a Teacher Console.
Does CVE-2023-28352 require Enhanced Security Mode to be disabled?
No, CVE-2023-28352 can still be exploited even if Enhanced Security Mode is enabled.