CVE-2023-33796: Critical severity netbox Netbox vulnerability
DISPUTED A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which is public; queries for database objects would have been denied.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Netbox vulnerability?
The vulnerability ID is CVE-2023-33796.
What is the severity level of vulnerability CVE-2023-33796?
The severity level of CVE-2023-33796 is critical (severity value: 9).
What is the affected software version for vulnerability CVE-2023-33796?
The affected software version for CVE-2023-33796 is Netbox v3.5.1.
How can an unauthenticated attacker exploit vulnerability CVE-2023-33796?
An unauthenticated attacker can exploit CVE-2023-33796 by executing queries against the GraphQL database of Netbox v3.5.1.
What data can an attacker access through vulnerability CVE-2023-33796?
An attacker can access sensitive data stored in the database of Netbox v3.5.1 through CVE-2023-33796.