CVE-2023-3425: Out-of-Bounds memory read
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-3425?
CVE-2023-3425 is an out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 that allows an unauthenticated user to read a restricted amount of bytes from memory.
How severe is CVE-2023-3425?
The severity of CVE-2023-3425 is medium with a CVSS score of 5.3.
Which software versions are affected by CVE-2023-3425?
M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 are affected by CVE-2023-3425.
How can an unauthenticated user exploit CVE-2023-3425?
An unauthenticated user can exploit CVE-2023-3425 by reading a restricted amount of bytes from memory.
Is there a fix available for CVE-2023-3425?
Yes, updating to M-Files Server version 23.8.12892.6 or LTS Service Release Version 23.2 LTS SR3 will fix CVE-2023-3425.