First published: Fri Aug 25 2023(Updated: )
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files Classic Web | <23.2 | |
M-Files Classic Web | <23.6.12695.3 | |
M-Files Classic Web | =23.2 |
Update to M-Files release versions 23.8 or newer, or update to LTS versions 23.2 SR3 or newer
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3425 is an out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 that allows an unauthenticated user to read a restricted amount of bytes from memory.
The severity of CVE-2023-3425 is medium with a CVSS score of 5.3.
M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 are affected by CVE-2023-3425.
An unauthenticated user can exploit CVE-2023-3425 by reading a restricted amount of bytes from memory.
Yes, updating to M-Files Server version 23.8.12892.6 or LTS Service Release Version 23.2 LTS SR3 will fix CVE-2023-3425.