CVE-2023-29065: Overly Permissive Access Policy
Published Nov 28, 2023
·Updated
The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in the database.
Affected Software
6 affected components
All of the following
Any of the following
BD Facschorus=5.0
BD Facschorus=5.1
HP Hp Z2 Tower G9
All of the following
Any of the following
BD Facschorus=3.0
BD Facschorus=3.1
HP Hp Z2 Tower G5
Event History
Nov 28, 2023
CVE Published
08:35 PM
Data Sourced
08:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-29065?
CVE-2023-29065 is a vulnerability that allows a threat actor with physical access to gain credentials and potentially alter or destroy data in the FACSChorus software database.
2
What software versions are affected by CVE-2023-29065?
The affected software versions are Bd Facschorus 5.0 and 5.1.
3
Is Hp Hp Z2 Tower G9 vulnerable to CVE-2023-29065?
No, Hp Hp Z2 Tower G9 is not vulnerable to CVE-2023-29065.
4
What is the severity of CVE-2023-29065?
The severity of CVE-2023-29065 is medium, with a CVSS score of 4.1.
5
How can I fix CVE-2023-29065?
To fix CVE-2023-29065, it is recommended to implement proper access controls and restrict direct database access.