CVE-2023-28870: Medium severity ncp-e secure enterprise client vulnerability
Published Dec 9, 2023
·Updated
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
Affected Software
1 affected component
ncp-e Secure Enterprise Client<12.22
Event History
Dec 9, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-28870?
CVE-2023-28870 has been classified as a medium-severity vulnerability due to insecure file permissions.
2
How do I fix CVE-2023-28870?
To mitigate CVE-2023-28870, ensure that correct permissions are set on configuration files to prevent unauthorized access.
3
Which versions of NCP Secure Enterprise Client are affected by CVE-2023-28870?
CVE-2023-28870 affects NCP Secure Enterprise Client versions prior to 12.22.
4
What type of vulnerability is CVE-2023-28870?
CVE-2023-28870 is classified as an insecure file permissions vulnerability.
5
Can low-privileged accounts exploit CVE-2023-28870?
Yes, low-privileged user accounts can exploit CVE-2023-28870 to write to configuration files.